Security Advisory mysql security update

Advisory: RHSA-2003:094-12
Type: Security Advisory
Severity: Important
Issued on: 2003-04-28
Last updated on: 2003-08-25
Affected Products: Red Hat Enterprise Linux AS (v. 2.1)
Red Hat Enterprise Linux ES (v. 2.1)
Red Hat Enterprise Linux WS (v. 2.1)
Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor
OVAL: N/A
CVEs (cve.mitre.org): CVE-2003-0073
CVE-2003-0150

Details

Updated packages are available that fix both a double-free security
vulnerability and a remote root exploit security vulnerability found in the
MySQL server.

[Updated 11 Aug 2003]
Updated mysqlclient9 packages are now included. These were previously
missing from this erratum.

MySQL is a multi-user, multi-threaded SQL database server.

A double-free vulnerability in mysqld, for MySQL before version 3.23.55,
allows attackers with MySQL access to cause a denial of service (crash) by
creating a carefully crafted client application.

A remote root exploit vulnerability in mysqld, for MySQL before version
3.23.56, allows MySQL users to gain root privileges by overwriting
configuration files.

Previous versions of the MySQL packages do not contain the thread safe
client library (libmysqlclient_r).

All users of MySQL are advised to upgrade to these errata packages
containing MySQL 3.23.56.


Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

Please note that this update is available via Red Hat Network. To use Red
Hat Network, launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.

Updated packages

Red Hat Enterprise Linux AS (v. 2.1)

SRPMS:
mysql-3.23.56-1.72.src.rpm
File outdated by:  RHSA-2005:334
    54f783324c224840fe7ea702fe628ec2
mysqlclient9-3.23.22-8.src.rpm     9c782173b553a1998d317c2477ed3247
 
IA-32:
mysql-3.23.56-1.72.i386.rpm
File outdated by:  RHSA-2005:334
    d1efdb7796e0444302ee3f426ca06c85
mysql-devel-3.23.56-1.72.i386.rpm
File outdated by:  RHSA-2005:334
    9b77319f6ecc7e5431efc99e7a291334
mysql-server-3.23.56-1.72.i386.rpm
File outdated by:  RHSA-2005:334
    ef3c7d3e1bfe3b835ee07b8d2eda7e21
mysqlclient9-3.23.22-8.i386.rpm     649000787148d19b8019919535845680
 
IA-64:
mysql-3.23.56-1.72.ia64.rpm
File outdated by:  RHSA-2005:334
    fcdac19a133fcf7feb34e06877ed1242
mysql-devel-3.23.56-1.72.ia64.rpm
File outdated by:  RHSA-2005:334
    6d5ed02bee3fe571275b5053cebc6c94
mysql-server-3.23.56-1.72.ia64.rpm
File outdated by:  RHSA-2005:334
    19737a4c7f39bd37fbd73d0388d2c847
 
Red Hat Enterprise Linux ES (v. 2.1)

SRPMS:
mysql-3.23.56-1.72.src.rpm
File outdated by:  RHSA-2005:334
    54f783324c224840fe7ea702fe628ec2
mysqlclient9-3.23.22-8.src.rpm     9c782173b553a1998d317c2477ed3247
 
IA-32:
mysql-3.23.56-1.72.i386.rpm
File outdated by:  RHSA-2005:334
    d1efdb7796e0444302ee3f426ca06c85
mysql-devel-3.23.56-1.72.i386.rpm
File outdated by:  RHSA-2005:334
    9b77319f6ecc7e5431efc99e7a291334
mysql-server-3.23.56-1.72.i386.rpm
File outdated by:  RHSA-2005:334
    ef3c7d3e1bfe3b835ee07b8d2eda7e21
mysqlclient9-3.23.22-8.i386.rpm     649000787148d19b8019919535845680
 
Red Hat Enterprise Linux WS (v. 2.1)

SRPMS:
mysql-3.23.56-1.72.src.rpm
File outdated by:  RHSA-2005:334
    54f783324c224840fe7ea702fe628ec2
mysqlclient9-3.23.22-8.src.rpm     9c782173b553a1998d317c2477ed3247
 
IA-32:
mysql-3.23.56-1.72.i386.rpm
File outdated by:  RHSA-2005:334
    d1efdb7796e0444302ee3f426ca06c85
mysql-devel-3.23.56-1.72.i386.rpm
File outdated by:  RHSA-2005:334
    9b77319f6ecc7e5431efc99e7a291334
mysql-server-3.23.56-1.72.i386.rpm
File outdated by:  RHSA-2005:334
    ef3c7d3e1bfe3b835ee07b8d2eda7e21
mysqlclient9-3.23.22-8.i386.rpm     649000787148d19b8019919535845680
 
Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor

SRPMS:
mysql-3.23.56-1.72.src.rpm
File outdated by:  RHSA-2005:334
    54f783324c224840fe7ea702fe628ec2
 
IA-64:
mysql-3.23.56-1.72.ia64.rpm
File outdated by:  RHSA-2005:334
    fcdac19a133fcf7feb34e06877ed1242
mysql-devel-3.23.56-1.72.ia64.rpm
File outdated by:  RHSA-2005:334
    6d5ed02bee3fe571275b5053cebc6c94
mysql-server-3.23.56-1.72.ia64.rpm
File outdated by:  RHSA-2005:334
    19737a4c7f39bd37fbd73d0388d2c847
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

77662 - mysql RPM's do not provide a thread safe library
85898 - double-free vulnerability in mysqld < 3.23.55
85971 - possible root exploit in mysqld startup


References


Keywords

mysql


These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/