Date: Wed, 23 May 2007 15:31:46 -0400
From: rPath Update Announcements <announce-noreply@rpath.com.>
To: [email protected],
Subject: rPSA-2007-0107-1 mysql mysql-bench mysql-server
Message-ID: <465496a2.78coSvU0zW5RTIRI%[email protected]>
User-Agent: nail 11.22 3/20/05
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
X-Virus-Scanned: antivirus-gw at tyumen.ru
rPath Security Advisory: 2007-0107-1
Published: 2007-05-23
Products: rPath Linux 1
Rating: Minor
Exposure Level Classification:
Local User Deterministic Denial of Service
Updated Versions:
mysql=/conary.rpath.com@rpl:devel//1/5.0.41-2-0.1
mysql-bench=/conary.rpath.com@rpl:devel//1/5.0.41-2-0.1
mysql-server=/conary.rpath.com@rpl:devel//1/5.0.41-2-0.1
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2583http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1420
https://issues.rpath.com/browse/RPL-1127
https://issues.rpath.com/browse/RPL-1356
Description:
Previous versions of the mysql package are vulnerable to two
authenticated-user denial of service attacks in which specially crafted
queries can be used to crash the server.
Copyright 2007 rPath, Inc.
This file is distributed under the terms of the MIT License.
A copy is available at http://www.rpath.com/permanent/mit-license.html