Updated mysql packages that fix multiple security flaws are now available.
This update has been rated as having important security impact by the Red Hat
Security Response Team.
MySQL is a multi-user, multi-threaded SQL database server. MySQL is a
client/server implementation consisting of a server daemon (mysqld) and
many different client programs and libraries.
A flaw was found in the way the MySQL mysql_real_escape() function escaped
strings when operating in a multibyte character encoding. An attacker
could provide an application a carefully crafted string containing
invalidly-encoded characters which may be improperly escaped, leading to
the injection of malicious SQL commands. (CVE-2006-2753)
An information disclosure flaw was found in the way the MySQL server
processed malformed usernames. An attacker could view a small portion
of server memory by supplying an anonymous login username which was not
null terminated. (CVE-2006-1516)
An information disclosure flaw was found in the way the MySQL server
executed the COM_TABLE_DUMP command. An authenticated malicious user could
send a specially crafted packet to the MySQL server which returned
random unallocated memory. (CVE-2006-1517)
A log file obfuscation flaw was found in the way the mysql_real_query()
function creates log file entries. An attacker with the the ability to call
the mysql_real_query() function against a mysql server can obfuscate the
entry the server will write to the log file. However, an attacker needed
to have complete control over a server in order to attempt this attack.
(CVE-2006-0903)
This update also fixes numerous non-security-related flaws, such as
intermittent authentication failures.
All users of mysql are advised to upgrade to these updated packages
containing MySQL version 4.1.20, which is not vulnerable to these issues.
| Red Hat Desktop (v. 4) |
|
| SRPMS: |
mysql-4.1.20-1.RHEL4.1.src.rpm
File outdated by: RHSA-2008:0768 |
a2f3a2d4debf79880185121dbbe44046 |
| |
| IA-32: |
mysql-4.1.20-1.RHEL4.1.i386.rpm
File outdated by: RHSA-2008:0768 |
08a2cb1c1b6d0a017d1dd8b0e146d753 |
mysql-bench-4.1.20-1.RHEL4.1.i386.rpm
File outdated by: RHSA-2008:0768 |
4c64c56cf7cd7e51b8af1ddc0d7f9927 |
mysql-devel-4.1.20-1.RHEL4.1.i386.rpm
File outdated by: RHSA-2008:0768 |
c8b580d2a1a92a11a2f493dba2b96159 |
mysql-server-4.1.20-1.RHEL4.1.i386.rpm
File outdated by: RHSA-2008:0768 |
8aa0d5a1d3600ff7896d82d69935aed3 |
| |
| x86_64: |
mysql-4.1.20-1.RHEL4.1.i386.rpm
File outdated by: RHSA-2008:0768 |
08a2cb1c1b6d0a017d1dd8b0e146d753 |
mysql-4.1.20-1.RHEL4.1.x86_64.rpm
File outdated by: RHSA-2008:0768 |
3c3d997209f94f16c296ec9022f0ae56 |
mysql-bench-4.1.20-1.RHEL4.1.x86_64.rpm
File outdated by: RHSA-2008:0768 |
9247f09ee8067fb2e233948399c2ee19 |
mysql-devel-4.1.20-1.RHEL4.1.x86_64.rpm
File outdated by: RHSA-2008:0768 |
6dd062482cf41bf37c426dbb7d5d19f7 |
mysql-server-4.1.20-1.RHEL4.1.x86_64.rpm
File outdated by: RHSA-2008:0768 |
3dc3e127614cc1d015ec43d34e5f66dd |
| |
| Red Hat Enterprise Linux AS (v. 4) |
|
| SRPMS: |
mysql-4.1.20-1.RHEL4.1.src.rpm
File outdated by: RHSA-2008:0768 |
a2f3a2d4debf79880185121dbbe44046 |
| |
| IA-32: |
mysql-4.1.20-1.RHEL4.1.i386.rpm
File outdated by: RHSA-2008:0768 |
08a2cb1c1b6d0a017d1dd8b0e146d753 |
mysql-bench-4.1.20-1.RHEL4.1.i386.rpm
File outdated by: RHSA-2008:0768 |
4c64c56cf7cd7e51b8af1ddc0d7f9927 |
mysql-devel-4.1.20-1.RHEL4.1.i386.rpm
File outdated by: RHSA-2008:0768 |
c8b580d2a1a92a11a2f493dba2b96159 |
mysql-server-4.1.20-1.RHEL4.1.i386.rpm
File outdated by: RHSA-2008:0768 |
8aa0d5a1d3600ff7896d82d69935aed3 |
| |
| IA-64: |
mysql-4.1.20-1.RHEL4.1.i386.rpm
File outdated by: RHSA-2008:0768 |
08a2cb1c1b6d0a017d1dd8b0e146d753 |
mysql-4.1.20-1.RHEL4.1.ia64.rpm
File outdated by: RHSA-2008:0768 |
31f495c09ada1272043c2f20d51da60f |
mysql-bench-4.1.20-1.RHEL4.1.ia64.rpm
File outdated by: RHSA-2008:0768 |
dd14f3e7d79bcb43249ac4ac8e1f0e94 |
mysql-devel-4.1.20-1.RHEL4.1.ia64.rpm
File outdated by: RHSA-2008:0768 |
645a30fe7523fabb1dad211122c91696 |
mysql-server-4.1.20-1.RHEL4.1.ia64.rpm
File outdated by: RHSA-2008:0768 |
862dc1e3420a5701a6cfba70637b9fb0 |
| |
| PPC: |
mysql-4.1.20-1.RHEL4.1.ppc.rpm
File outdated by: RHSA-2008:0768 |
73930f1ecacdf0104a5fa0eb26991af5 |
mysql-4.1.20-1.RHEL4.1.ppc64.rpm
File outdated by: RHSA-2008:0768 |
fb6cd06215f42871c55040072bef98de |
mysql-bench-4.1.20-1.RHEL4.1.ppc.rpm
File outdated by: RHSA-2008:0768 |
324850079285509d584b626966f89843 |
mysql-devel-4.1.20-1.RHEL4.1.ppc.rpm
File outdated by: RHSA-2008:0768 |
217f143cc4e238fab9be84224e224635 |
mysql-server-4.1.20-1.RHEL4.1.ppc.rpm
File outdated by: RHSA-2008:0768 |
9030e10ce11abc622e8199a3b4556a98 |
| |
| s390: |
mysql-4.1.20-1.RHEL4.1.s390.rpm
File outdated by: RHSA-2008:0768 |
ffcae0f612254941d5ad5456f0ac01ad |
mysql-bench-4.1.20-1.RHEL4.1.s390.rpm
File outdated by: RHSA-2008:0768 |
4e73c481e7694d273855f11008297075 |
mysql-devel-4.1.20-1.RHEL4.1.s390.rpm
File outdated by: RHSA-2008:0768 |
0c8cf2d8bbb3a612448715678ffdcd8d |
mysql-server-4.1.20-1.RHEL4.1.s390.rpm
File outdated by: RHSA-2008:0768 |
dac602ffe37660b8e3c01ecfeb910337 |
| |
| s390x: |
mysql-4.1.20-1.RHEL4.1.s390.rpm
File outdated by: RHSA-2008:0768 |
ffcae0f612254941d5ad5456f0ac01ad |
mysql-4.1.20-1.RHEL4.1.s390x.rpm
File outdated by: RHSA-2008:0768 |
63bae1479ea4798b2d0baa5478819402 |
mysql-bench-4.1.20-1.RHEL4.1.s390x.rpm
File outdated by: RHSA-2008:0768 |
739d66b027e6ba5a7826e7b039bc7060 |
mysql-devel-4.1.20-1.RHEL4.1.s390x.rpm
File outdated by: RHSA-2008:0768 |
3463483049e38a6fbd4ee34f427ac869 |
mysql-server-4.1.20-1.RHEL4.1.s390x.rpm
File outdated by: RHSA-2008:0768 |
20870248905a1c3af1bf6b17688b5843 |
| |
| x86_64: |
mysql-4.1.20-1.RHEL4.1.i386.rpm
File outdated by: RHSA-2008:0768 |
08a2cb1c1b6d0a017d1dd8b0e146d753 |
mysql-4.1.20-1.RHEL4.1.x86_64.rpm
File outdated by: RHSA-2008:0768 |
3c3d997209f94f16c296ec9022f0ae56 |
mysql-bench-4.1.20-1.RHEL4.1.x86_64.rpm
File outdated by: RHSA-2008:0768 |
9247f09ee8067fb2e233948399c2ee19 |
mysql-devel-4.1.20-1.RHEL4.1.x86_64.rpm
File outdated by: RHSA-2008:0768 |
6dd062482cf41bf37c426dbb7d5d19f7 |
mysql-server-4.1.20-1.RHEL4.1.x86_64.rpm
File outdated by: RHSA-2008:0768 |
3dc3e127614cc1d015ec43d34e5f66dd |
| |
| Red Hat Enterprise Linux ES (v. 4) |
|
| SRPMS: |
mysql-4.1.20-1.RHEL4.1.src.rpm
File outdated by: RHSA-2008:0768 |
a2f3a2d4debf79880185121dbbe44046 |
| |
| IA-32: |
mysql-4.1.20-1.RHEL4.1.i386.rpm
File outdated by: RHSA-2008:0768 |
08a2cb1c1b6d0a017d1dd8b0e146d753 |
mysql-bench-4.1.20-1.RHEL4.1.i386.rpm
File outdated by: RHSA-2008:0768 |
4c64c56cf7cd7e51b8af1ddc0d7f9927 |
mysql-devel-4.1.20-1.RHEL4.1.i386.rpm
File outdated by: RHSA-2008:0768 |
c8b580d2a1a92a11a2f493dba2b96159 |
mysql-server-4.1.20-1.RHEL4.1.i386.rpm
File outdated by: RHSA-2008:0768 |
8aa0d5a1d3600ff7896d82d69935aed3 |
| |
| IA-64: |
mysql-4.1.20-1.RHEL4.1.i386.rpm
File outdated by: RHSA-2008:0768 |
08a2cb1c1b6d0a017d1dd8b0e146d753 |
mysql-4.1.20-1.RHEL4.1.ia64.rpm
File outdated by: RHSA-2008:0768 |
31f495c09ada1272043c2f20d51da60f |
mysql-bench-4.1.20-1.RHEL4.1.ia64.rpm
File outdated by: RHSA-2008:0768 |
dd14f3e7d79bcb43249ac4ac8e1f0e94 |
mysql-devel-4.1.20-1.RHEL4.1.ia64.rpm
File outdated by: RHSA-2008:0768 |
645a30fe7523fabb1dad211122c91696 |
mysql-server-4.1.20-1.RHEL4.1.ia64.rpm
File outdated by: RHSA-2008:0768 |
862dc1e3420a5701a6cfba70637b9fb0 |
| |
| x86_64: |
mysql-4.1.20-1.RHEL4.1.i386.rpm
File outdated by: RHSA-2008:0768 |
08a2cb1c1b6d0a017d1dd8b0e146d753 |
mysql-4.1.20-1.RHEL4.1.x86_64.rpm
File outdated by: RHSA-2008:0768 |
3c3d997209f94f16c296ec9022f0ae56 |
mysql-bench-4.1.20-1.RHEL4.1.x86_64.rpm
File outdated by: RHSA-2008:0768 |
9247f09ee8067fb2e233948399c2ee19 |
mysql-devel-4.1.20-1.RHEL4.1.x86_64.rpm
File outdated by: RHSA-2008:0768 |
6dd062482cf41bf37c426dbb7d5d19f7 |
mysql-server-4.1.20-1.RHEL4.1.x86_64.rpm
File outdated by: RHSA-2008:0768 |
3dc3e127614cc1d015ec43d34e5f66dd |
| |
| Red Hat Enterprise Linux WS (v. 4) |
|
| SRPMS: |
mysql-4.1.20-1.RHEL4.1.src.rpm
File outdated by: RHSA-2008:0768 |
a2f3a2d4debf79880185121dbbe44046 |
| |
| IA-32: |
mysql-4.1.20-1.RHEL4.1.i386.rpm
File outdated by: RHSA-2008:0768 |
08a2cb1c1b6d0a017d1dd8b0e146d753 |
mysql-bench-4.1.20-1.RHEL4.1.i386.rpm
File outdated by: RHSA-2008:0768 |
4c64c56cf7cd7e51b8af1ddc0d7f9927 |
mysql-devel-4.1.20-1.RHEL4.1.i386.rpm
File outdated by: RHSA-2008:0768 |
c8b580d2a1a92a11a2f493dba2b96159 |
mysql-server-4.1.20-1.RHEL4.1.i386.rpm
File outdated by: RHSA-2008:0768 |
8aa0d5a1d3600ff7896d82d69935aed3 |
| |
| IA-64: |
mysql-4.1.20-1.RHEL4.1.i386.rpm
File outdated by: RHSA-2008:0768 |
08a2cb1c1b6d0a017d1dd8b0e146d753 |
mysql-4.1.20-1.RHEL4.1.ia64.rpm
File outdated by: RHSA-2008:0768 |
31f495c09ada1272043c2f20d51da60f |
mysql-bench-4.1.20-1.RHEL4.1.ia64.rpm
File outdated by: RHSA-2008:0768 |
dd14f3e7d79bcb43249ac4ac8e1f0e94 |
mysql-devel-4.1.20-1.RHEL4.1.ia64.rpm
File outdated by: RHSA-2008:0768 |
645a30fe7523fabb1dad211122c91696 |
mysql-server-4.1.20-1.RHEL4.1.ia64.rpm
File outdated by: RHSA-2008:0768 |
862dc1e3420a5701a6cfba70637b9fb0 |
| |
| x86_64: |
mysql-4.1.20-1.RHEL4.1.i386.rpm
File outdated by: RHSA-2008:0768 |
08a2cb1c1b6d0a017d1dd8b0e146d753 |
mysql-4.1.20-1.RHEL4.1.x86_64.rpm
File outdated by: RHSA-2008:0768 |
3c3d997209f94f16c296ec9022f0ae56 |
mysql-bench-4.1.20-1.RHEL4.1.x86_64.rpm
File outdated by: RHSA-2008:0768 |
9247f09ee8067fb2e233948399c2ee19 |
mysql-devel-4.1.20-1.RHEL4.1.x86_64.rpm
File outdated by: RHSA-2008:0768 |
6dd062482cf41bf37c426dbb7d5d19f7 |
mysql-server-4.1.20-1.RHEL4.1.x86_64.rpm
File outdated by: RHSA-2008:0768 |
3dc3e127614cc1d015ec43d34e5f66dd |
| |
(The unlinked packages above are only available from the Red Hat Network)
|
183260 - CVE-2006-0903 Mysql log file obfuscation
183277 - Client error in mysql on updates when high concurrency
190743 - CVE-2006-1517 Mysql information leak
190863 - CVE-2006-1516 mysql anonymous login information leak
193827 - CVE-2006-2753 MySQL improper multibyte string escaping