NASLDB: SUSE-SA:2003:042: mysql
General
ID: 13810
Name: SUSE-SA:2003:042: mysql
Summary: Check for the version of the mysql package
Credits: Tenable Network Security, Inc.
Classification
Risk: –
CVSS: –
CVSS Base Vector: –
CVSS Temporal Vector: –
Port: –
Family: SuSE Local Security Checks
Type: –
Description
The remote host is missing the patch for the advisory SUSE-SA:2003:042 (mysql).
A remotely exploitable buffer overflow within the authentication code
of MySQL has been reported. This allows remote attackers who have
access to the ‘User’ table to execute arbitrary commands as mysql user.
The list of affected packages is as follows:
mysql, mysql-client, mysql-shared, mysql-bench, mysql-devel, mysql-Max.
In this advisory the MD5 sums for the mysql, mysql-shared and mysql-devel
packages are listed.
To be sure the update takes effect you have to restart the MySQL server
by executing the following command as root:
/usr/sbin/rcmysql restart
Please download the update package for your distribution and verify its
integrity by the methods listed in section 3) of this announcement.
Then, install the package using the command ‘rpm -Fhv file.rpm’ to apply
the update.
Exploiting
Exploit Available: –
Exploitability Ease: –
Sources
CVE: –
OSVDB: –
Bugtraq: –
scipID: –
Timeline
Vulnerability Disclosure: –
Patch Release: –
Plugin Release: 2004/07/25
Plugin
Version: 1.7
Filename: suse_SA_2003_042.nasl
Filesize: 3768 bytes
MD5 Hash: f37876b59b7acca340dcf1370567d961
Identification: –
Require Keys: Host/SuSE/rpm-list
Dependencies: "ssh_get_info.nasl"
Copyright: This script is Copyright© 2004-2010 Tenable Network Security, Inc.
- Letzte Plugins
- USN-1611-1 : thunderbird vulnerabilities
- USN-1610-1 : linux vulnerability
- USN-1609-1 : linux-ti-omap4 vulnerability
- SuSE 10 Security Update : PostgreSQL
- RHSA-2012-1364: bind97
- RHSA-2012-1363: bind
- RHSA-2012-1362: thunderbird
- RHSA-2012-1361: xulrunner
- Mandriva Linux Security Advisory : graphicsmagick
- FreeBSD : phpMyAdmin — Multiple XSS due to unescaped HTML output in Trigger, Procedure and Event pages and Fetching the version information from a non-SSL site is vulnerable to a MITM attack













