Updated MySQL packages for the Red Hat Application Stack comprising the v1.2
release fixed various security issues.
The security issues in this errata are rated as having important security
impact by the Red Hat Security Response Team.
On the 23rd August 2007, Red Hat Application Stack v1.2 was released. This
release contained a new version of MySQL that corrected several security
issues found in the MySQL packages of Red Hat Application Stack v1.1.
Users who have already updated to Red Hat Application Stack v1.2 will
already have the new MySQL packages and are not affected by these issues.
A flaw was discovered in MySQL's authentication protocol. A remote
unauthenticated attacker could send a specially crafted authentication
request to the MySQL server causing it to crash. (CVE-2007-3780)
MySQL did not require privileges such as SELECT for the source table in a
CREATE TABLE LIKE statement. A remote authenticated user could obtain
sensitive information such as the table structure. (CVE-2007-3781)
A flaw was discovered in MySQL that allowed remote authenticated
users to gain update privileges for a table in another database via a view
that refers to the external table (CVE-2007-3782).
A flaw was discovered in the mysql_change_db function when returning from
SQL SECURITY INVOKER stored routines. A remote authenticated user could
use this flaw to gain database privileges. (CVE-2007-2692)
MySQL did not require the DROP privilege for RENAME TABLE statements. A
remote authenticated users could use this flaw to rename arbitrary tables.
(CVE-2007-2691)
| Red Hat Application Stack v1 for Enterprise Linux AS (v.4) |
|
| SRPMS: |
mysql-5.0.44-1.el4s1.1.src.rpm
File outdated by: RHSA-2008:0510 |
9cbddb080cbaf79a86796a51b2a157b6 |
| |
| IA-32: |
mysql-5.0.44-1.el4s1.1.i386.rpm
File outdated by: RHSA-2008:0510 |
c37e8a5e4354a32cec55905395d9252e |
mysql-bench-5.0.44-1.el4s1.1.i386.rpm
File outdated by: RHSA-2008:0510 |
24e9b72f764bd9bd8de3752155e5ccf1 |
mysql-cluster-5.0.44-1.el4s1.1.i386.rpm
File outdated by: RHSA-2008:0510 |
1649ae3a0a993107a5378399b1f51212 |
mysql-devel-5.0.44-1.el4s1.1.i386.rpm
File outdated by: RHSA-2008:0510 |
557c5a41c93cff87c59579bb36cb4d02 |
mysql-libs-5.0.44-1.el4s1.1.i386.rpm
File outdated by: RHSA-2008:0510 |
e157cc468767d85e2bd437577fa0a1ea |
mysql-server-5.0.44-1.el4s1.1.i386.rpm
File outdated by: RHSA-2008:0510 |
a46bf4a951111094871dcd67d3b160c6 |
mysql-test-5.0.44-1.el4s1.1.i386.rpm
File outdated by: RHSA-2008:0510 |
2445d7641bae80e115a9d3a6f7bbdadc |
| |
| x86_64: |
mysql-5.0.44-1.el4s1.1.i386.rpm
File outdated by: RHSA-2008:0510 |
c37e8a5e4354a32cec55905395d9252e |
mysql-5.0.44-1.el4s1.1.x86_64.rpm
File outdated by: RHSA-2008:0510 |
d03ec02590a6ce1d1090a1f8d12cc970 |
mysql-bench-5.0.44-1.el4s1.1.x86_64.rpm
File outdated by: RHSA-2008:0510 |
a70972fdc4d3020059c58b9bf24224de |
mysql-cluster-5.0.44-1.el4s1.1.x86_64.rpm
File outdated by: RHSA-2008:0510 |
7296fe8d2b7657867df7c48f7eff9164 |
mysql-devel-5.0.44-1.el4s1.1.x86_64.rpm
File outdated by: RHSA-2008:0510 |
66dd9230aaa7b36e2a3fb3cc08271d54 |
mysql-libs-5.0.44-1.el4s1.1.i386.rpm
File outdated by: RHSA-2008:0510 |
e157cc468767d85e2bd437577fa0a1ea |
mysql-libs-5.0.44-1.el4s1.1.x86_64.rpm
File outdated by: RHSA-2008:0510 |
0a908c5f3cad66ebd72e9722f11c9216 |
mysql-server-5.0.44-1.el4s1.1.x86_64.rpm
File outdated by: RHSA-2008:0510 |
193a45c2fbc3153b462a5ca6f7aeafc7 |
mysql-test-5.0.44-1.el4s1.1.x86_64.rpm
File outdated by: RHSA-2008:0510 |
7c23107ea5f1da91f8b6fc730933e1fc |
| |
| Red Hat Application Stack v1 for Enterprise Linux ES (v.4) |
|
| SRPMS: |
mysql-5.0.44-1.el4s1.1.src.rpm
File outdated by: RHSA-2008:0510 |
9cbddb080cbaf79a86796a51b2a157b6 |
| |
| IA-32: |
mysql-5.0.44-1.el4s1.1.i386.rpm
File outdated by: RHSA-2008:0510 |
c37e8a5e4354a32cec55905395d9252e |
mysql-bench-5.0.44-1.el4s1.1.i386.rpm
File outdated by: RHSA-2008:0510 |
24e9b72f764bd9bd8de3752155e5ccf1 |
mysql-cluster-5.0.44-1.el4s1.1.i386.rpm
File outdated by: RHSA-2008:0510 |
1649ae3a0a993107a5378399b1f51212 |
mysql-devel-5.0.44-1.el4s1.1.i386.rpm
File outdated by: RHSA-2008:0510 |
557c5a41c93cff87c59579bb36cb4d02 |
mysql-libs-5.0.44-1.el4s1.1.i386.rpm
File outdated by: RHSA-2008:0510 |
e157cc468767d85e2bd437577fa0a1ea |
mysql-server-5.0.44-1.el4s1.1.i386.rpm
File outdated by: RHSA-2008:0510 |
a46bf4a951111094871dcd67d3b160c6 |
mysql-test-5.0.44-1.el4s1.1.i386.rpm
File outdated by: RHSA-2008:0510 |
2445d7641bae80e115a9d3a6f7bbdadc |
| |
| x86_64: |
mysql-5.0.44-1.el4s1.1.i386.rpm
File outdated by: RHSA-2008:0510 |
c37e8a5e4354a32cec55905395d9252e |
mysql-5.0.44-1.el4s1.1.x86_64.rpm
File outdated by: RHSA-2008:0510 |
d03ec02590a6ce1d1090a1f8d12cc970 |
mysql-bench-5.0.44-1.el4s1.1.x86_64.rpm
File outdated by: RHSA-2008:0510 |
a70972fdc4d3020059c58b9bf24224de |
mysql-cluster-5.0.44-1.el4s1.1.x86_64.rpm
File outdated by: RHSA-2008:0510 |
7296fe8d2b7657867df7c48f7eff9164 |
mysql-devel-5.0.44-1.el4s1.1.x86_64.rpm
File outdated by: RHSA-2008:0510 |
66dd9230aaa7b36e2a3fb3cc08271d54 |
mysql-libs-5.0.44-1.el4s1.1.i386.rpm
File outdated by: RHSA-2008:0510 |
e157cc468767d85e2bd437577fa0a1ea |
mysql-libs-5.0.44-1.el4s1.1.x86_64.rpm
File outdated by: RHSA-2008:0510 |
0a908c5f3cad66ebd72e9722f11c9216 |
mysql-server-5.0.44-1.el4s1.1.x86_64.rpm
File outdated by: RHSA-2008:0510 |
193a45c2fbc3153b462a5ca6f7aeafc7 |
mysql-test-5.0.44-1.el4s1.1.x86_64.rpm
File outdated by: RHSA-2008:0510 |
7c23107ea5f1da91f8b6fc730933e1fc |
| |
(The unlinked packages above are only available from the Red Hat Network)
|
241688 - CVE-2007-2691 DROP privilege is not enforced when renaming tables
241689 - CVE-2007-2692 SECURITY INVOKER functions do not drop privilegies
248553 - CVE-2007-3781 CVE-2007-3782 New release of MySQL fixes security bugs
254108 - CVE-2007-3780 mysql malformed password crasher