Security Advisory mysql security update

Advisory: RHSA-2004:569-16
Type: Security Advisory
Severity: Low
Issued on: 2004-10-20
Last updated on: 2004-10-20
Affected Products: Red Hat Desktop (v. 3)
Red Hat Enterprise Linux AS (v. 3)
Red Hat Enterprise Linux ES (v. 3)
Red Hat Enterprise Linux WS (v. 3)
OVAL: N/A
CVEs (cve.mitre.org): CVE-2004-0381
CVE-2004-0388
CVE-2004-0457

Details

Updated mysql packages that fix various temporary file security issues,
as well as a number of bugs, are now available.

MySQL is a multi-user, multi-threaded SQL database server.

This update fixes a number of small bugs, including some potential
security problems associated with careless handling of temporary files.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the names CAN-2004-0381, CAN-2004-0388, and CAN-2004-0457 to these
issues.

A number of additional security issues that affect mysql have been
corrected in the source package. These include CAN-2004-0835,
CAN-2004-0836, CAN-2004-0837, and CAN-2004-0957. Red Hat Enterprise Linux
3 does not ship with the mysql-server package and is therefore not affected
by these issues.

This update also allows 32-bit and 64-bit libraries to be installed
concurrently on the same system.

All users of mysql should upgrade to these updated packages, which resolve
these issues.


Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied. Use Red Hat
Network to download and update your packages. To launch the Red Hat
Update Agent, use the following command:

up2date

For information on how to install packages manually, refer to the
following Web page for the System Administration or Customization
guide specific to your system:

http://www.redhat.com/docs/manuals/enterprise/

Updated packages

Red Hat Desktop (v. 3)

SRPMS:
mysql-3.23.58-2.3.src.rpm
File outdated by:  RHBA-2006:0274
    3fea570d29c4a66fd5578705fd3a5f08
 
IA-32:
mysql-3.23.58-2.3.i386.rpm
File outdated by:  RHBA-2006:0274
    a5291f0504a64c7640818b554b2ec268
mysql-bench-3.23.58-2.3.i386.rpm
File outdated by:  RHBA-2006:0274
    d8d9f29055d4f9ac2bd0c577cf3c9f1a
mysql-devel-3.23.58-2.3.i386.rpm
File outdated by:  RHBA-2006:0274
    942437a7d22c99a96ccbc1fe30e01857
 
x86_64:
mysql-3.23.58-2.3.i386.rpm
File outdated by:  RHBA-2006:0274
    a5291f0504a64c7640818b554b2ec268
mysql-3.23.58-2.3.x86_64.rpm
File outdated by:  RHBA-2006:0274
    f11ffaa788c38434a7259bccf485b1a0
mysql-bench-3.23.58-2.3.x86_64.rpm
File outdated by:  RHBA-2006:0274
    9c20d57a7c724de9cd30a7a8be88fa1e
mysql-devel-3.23.58-2.3.x86_64.rpm
File outdated by:  RHBA-2006:0274
    14a7a2b00486de17c287bf90010b7377
 
Red Hat Enterprise Linux AS (v. 3)

SRPMS:
mysql-3.23.58-2.3.src.rpm
File outdated by:  RHBA-2006:0274
    3fea570d29c4a66fd5578705fd3a5f08
 
IA-32:
mysql-3.23.58-2.3.i386.rpm
File outdated by:  RHBA-2006:0274
    a5291f0504a64c7640818b554b2ec268
mysql-bench-3.23.58-2.3.i386.rpm
File outdated by:  RHBA-2006:0274
    d8d9f29055d4f9ac2bd0c577cf3c9f1a
mysql-devel-3.23.58-2.3.i386.rpm
File outdated by:  RHBA-2006:0274
    942437a7d22c99a96ccbc1fe30e01857
 
IA-64:
mysql-3.23.58-2.3.i386.rpm
File outdated by:  RHBA-2006:0274
    a5291f0504a64c7640818b554b2ec268
mysql-3.23.58-2.3.ia64.rpm
File outdated by:  RHBA-2006:0274
    273e64f3bc444f642cc27e149047e88b
mysql-bench-3.23.58-2.3.ia64.rpm
File outdated by:  RHBA-2006:0274
    035537b43e8860f4713bb8ba2f434376
mysql-devel-3.23.58-2.3.ia64.rpm
File outdated by:  RHBA-2006:0274
    b10cfeaa55f652962f424036f6dd169b
 
PPC:
mysql-3.23.58-2.3.ppc.rpm
File outdated by:  RHBA-2006:0274
    22972cd7c174cd85e0c08cf6232d90c2
mysql-3.23.58-2.3.ppc64.rpm
File outdated by:  RHBA-2006:0274
    552fb60408534cc09ea24f7a141a016b
mysql-bench-3.23.58-2.3.ppc.rpm
File outdated by:  RHBA-2006:0274
    3d2f07341d89c5793f56dc9879b4c4e6
mysql-devel-3.23.58-2.3.ppc.rpm
File outdated by:  RHBA-2006:0274
    2a3bb5baaecc6f1101d2a9d2c0f0938b
 
s390:
mysql-3.23.58-2.3.s390.rpm
File outdated by:  RHBA-2006:0274
    f47fbbc3e354853485c5424dc22ccc8c
mysql-bench-3.23.58-2.3.s390.rpm
File outdated by:  RHBA-2006:0274
    973e0714e31de71c0efad0599941bb7e
mysql-devel-3.23.58-2.3.s390.rpm
File outdated by:  RHBA-2006:0274
    6efe72cbdabdde4e2d3db8c24d5e8e24
 
s390x:
mysql-3.23.58-2.3.s390.rpm
File outdated by:  RHBA-2006:0274
    f47fbbc3e354853485c5424dc22ccc8c
mysql-3.23.58-2.3.s390x.rpm
File outdated by:  RHBA-2006:0274
    e525bd1a40a1157ff99f79006d8447fe
mysql-bench-3.23.58-2.3.s390x.rpm
File outdated by:  RHBA-2006:0274
    62bc707e3a3a6444e7dad5fd0947249a
mysql-devel-3.23.58-2.3.s390x.rpm
File outdated by:  RHBA-2006:0274
    a07377d3c15bcbf4a978676036a04d76
 
x86_64:
mysql-3.23.58-2.3.i386.rpm
File outdated by:  RHBA-2006:0274
    a5291f0504a64c7640818b554b2ec268
mysql-3.23.58-2.3.x86_64.rpm
File outdated by:  RHBA-2006:0274
    f11ffaa788c38434a7259bccf485b1a0
mysql-bench-3.23.58-2.3.x86_64.rpm
File outdated by:  RHBA-2006:0274
    9c20d57a7c724de9cd30a7a8be88fa1e
mysql-devel-3.23.58-2.3.x86_64.rpm
File outdated by:  RHBA-2006:0274
    14a7a2b00486de17c287bf90010b7377
 
Red Hat Enterprise Linux ES (v. 3)

SRPMS:
mysql-3.23.58-2.3.src.rpm
File outdated by:  RHBA-2006:0274
    3fea570d29c4a66fd5578705fd3a5f08
 
IA-32:
mysql-3.23.58-2.3.i386.rpm
File outdated by:  RHBA-2006:0274
    a5291f0504a64c7640818b554b2ec268
mysql-bench-3.23.58-2.3.i386.rpm
File outdated by:  RHBA-2006:0274
    d8d9f29055d4f9ac2bd0c577cf3c9f1a
mysql-devel-3.23.58-2.3.i386.rpm
File outdated by:  RHBA-2006:0274
    942437a7d22c99a96ccbc1fe30e01857
 
IA-64:
mysql-3.23.58-2.3.i386.rpm
File outdated by:  RHBA-2006:0274
    a5291f0504a64c7640818b554b2ec268
mysql-3.23.58-2.3.ia64.rpm
File outdated by:  RHBA-2006:0274
    273e64f3bc444f642cc27e149047e88b
mysql-bench-3.23.58-2.3.ia64.rpm
File outdated by:  RHBA-2006:0274
    035537b43e8860f4713bb8ba2f434376
mysql-devel-3.23.58-2.3.ia64.rpm
File outdated by:  RHBA-2006:0274
    b10cfeaa55f652962f424036f6dd169b
 
x86_64:
mysql-3.23.58-2.3.i386.rpm
File outdated by:  RHBA-2006:0274
    a5291f0504a64c7640818b554b2ec268
mysql-3.23.58-2.3.x86_64.rpm
File outdated by:  RHBA-2006:0274
    f11ffaa788c38434a7259bccf485b1a0
mysql-bench-3.23.58-2.3.x86_64.rpm
File outdated by:  RHBA-2006:0274
    9c20d57a7c724de9cd30a7a8be88fa1e
mysql-devel-3.23.58-2.3.x86_64.rpm
File outdated by:  RHBA-2006:0274
    14a7a2b00486de17c287bf90010b7377
 
Red Hat Enterprise Linux WS (v. 3)

SRPMS:
mysql-3.23.58-2.3.src.rpm
File outdated by:  RHBA-2006:0274
    3fea570d29c4a66fd5578705fd3a5f08
 
IA-32:
mysql-3.23.58-2.3.i386.rpm
File outdated by:  RHBA-2006:0274
    a5291f0504a64c7640818b554b2ec268
mysql-bench-3.23.58-2.3.i386.rpm
File outdated by:  RHBA-2006:0274
    d8d9f29055d4f9ac2bd0c577cf3c9f1a
mysql-devel-3.23.58-2.3.i386.rpm
File outdated by:  RHBA-2006:0274
    942437a7d22c99a96ccbc1fe30e01857
 
IA-64:
mysql-3.23.58-2.3.i386.rpm
File outdated by:  RHBA-2006:0274
    a5291f0504a64c7640818b554b2ec268
mysql-3.23.58-2.3.ia64.rpm
File outdated by:  RHBA-2006:0274
    273e64f3bc444f642cc27e149047e88b
mysql-bench-3.23.58-2.3.ia64.rpm
File outdated by:  RHBA-2006:0274
    035537b43e8860f4713bb8ba2f434376
mysql-devel-3.23.58-2.3.ia64.rpm
File outdated by:  RHBA-2006:0274
    b10cfeaa55f652962f424036f6dd169b
 
x86_64:
mysql-3.23.58-2.3.i386.rpm
File outdated by:  RHBA-2006:0274
    a5291f0504a64c7640818b554b2ec268
mysql-3.23.58-2.3.x86_64.rpm
File outdated by:  RHBA-2006:0274
    f11ffaa788c38434a7259bccf485b1a0
mysql-bench-3.23.58-2.3.x86_64.rpm
File outdated by:  RHBA-2006:0274
    9c20d57a7c724de9cd30a7a8be88fa1e
mysql-devel-3.23.58-2.3.x86_64.rpm
File outdated by:  RHBA-2006:0274
    14a7a2b00486de17c287bf90010b7377
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

102190 - specfile contains improper log details in %files
108779 - Always timeout error starting MySQL Daemon
112693 - mysqlhotcopy of local Fedora DB broken after upgrade from RH9
113960 - [PATCH] Bug fix + enhancement for mysql_setpermission
115165 - botched string concat ?
117017 - RHEL2.1: removing mysql-server does not remove the mysql user.
119442 - CAN-2004-0381 mysqlbug temporary file vulnerability
124352 - Cannot drop databases
128852 - database service should start earlier
129409 - linking with 'mysql --libs' doesent seem to work correctly.
130348 - CAN-2004-0457 mysqlhotcopy insecure temporary file vulnerability
133993 - Service mysqld restart
135387 - CAN-2004-0835 MySQL flaws (CAN-2004-0836, CAN-2004-0837, CAN-2004-0957)
58732 - /etc/init.d/mysqld doesn't wait for server to start


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/