[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2581-1 mysql-5.1 -- several

ID: oval:org.secpod.oval:def:600922Date: (C)2012-12-04   (M)2023-12-07
Class: PATCHFamily: unix




Several issues have been discovered in the MySQL database server. The vulnerabilities are addressed by upgrading MySQL to a new upstream version, 5.1.66, which includes additional changes, such as performance improvements and corrections for data loss defects. Additionally, CVE-2012-5611 has been fixed in this upload. The vulnerability is a stack-based buffer overflow in acl_get when checking user access to a database. Using a carefully crafted database name, an already authenticated MySQL user could make the server crash or even execute arbitrary code as the mysql system user.

Platform:
Debian 6.0
Product:
mysql-server-5.1
Reference:
DSA-2581-1
CVE-2012-3150
CVE-2012-3158
CVE-2012-3160
CVE-2012-3163
CVE-2012-3166
CVE-2012-3167
CVE-2012-3173
CVE-2012-3177
CVE-2012-3180
CVE-2012-3197
CVE-2012-5611
CVE    11
CVE-2012-3166
CVE-2012-3177
CVE-2012-3167
CVE-2012-3158
...
CPE    2
cpe:/o:debian:debian_linux:6.0
cpe:/a:mysql:mysql_server:5.1

© SecPod Technologies