Login
Newsletter
Werbung

Sicherheit: Mangelnde Rechteprüfung in MySQL
Aktuelle Meldungen Distributionen
Name: Mangelnde Rechteprüfung in MySQL
ID: USN-1467-1
Distribution: Ubuntu
Plattformen: Ubuntu 8.04 LTS, Ubuntu 10.04 LTS, Ubuntu 11.04, Ubuntu 11.10, Ubuntu 12.04 LTS
Datum: Di, 12. Juni 2012, 08:19
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2122
http://dev.mysql.com/doc/refman/5.1/en/news-5-1-63.html
http://dev.mysql.com/doc/refman/5.5/en/news-5-5-24.html
Applikationen: MySQL

Originalnachricht


--===============6964890179595402623==
Content-Type: multipart/signed; micalg="pgp-sha512";
protocol="application/pgp-signature";
boundary="=-PJ2Wsl/hi+uNnGbppLdn"


--=-PJ2Wsl/hi+uNnGbppLdn
Content-Type: text/plain; charset="UTF-8
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-1467-1
June 11, 2012

mysql-5.1, mysql-5.5, mysql-dfsg-5.0, mysql-dfsg-5.1 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS
- Ubuntu 11.10
- Ubuntu 11.04
- Ubuntu 10.04 LTS
- Ubuntu 8.04 LTS

Summary:

Several security issues were fixed in MySQL.

Software Description:
- mysql-5.5: MySQL database
- mysql-5.1: MySQL database
- mysql-dfsg-5.1: MySQL database
- mysql-dfsg-5.0: MySQL database

Details:

It was discovered that certain builds of MySQL incorrectly handled password
authentication on certain platforms. A remote attacker could use this issue
to authenticate with an arbitrary password and establish a connection.
(CVE-2012-2122)

MySQL has been updated to 5.5.24 in Ubuntu 12.04 LTS. Ubuntu 10.04 LTS,
Ubuntu 11.04 and Ubuntu 11.10 have been updated to MySQL 5.1.63. A patch to
fix the issue was backported to the version of MySQL in Ubuntu 8.04 LTS.

In addition to additional security fixes, the updated packages contain bug
fixes, new features, and possibly incompatible changes.

Please see the following for more information:

http://dev.mysql.com/doc/refman/5.5/en/news-5-5-24.html
http://dev.mysql.com/doc/refman/5.1/en/news-5-1-63.html

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
mysql-server-5.5 5.5.24-0ubuntu0.12.04.1

Ubuntu 11.10:
mysql-server-5.1 5.1.63-0ubuntu0.11.10.1

Ubuntu 11.04:
mysql-server-5.1 5.1.63-0ubuntu0.11.04.1

Ubuntu 10.04 LTS:
mysql-server-5.1 5.1.63-0ubuntu0.10.04.1

Ubuntu 8.04 LTS:
mysql-server-5.0 5.0.96-0ubuntu3

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1467-1
CVE-2012-2122

Package Information:
https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.24-0ubuntu0.12.04.1
https://launchpad.net/ubuntu/+source/mysql-5.1/5.1.63-0ubuntu0.11.10.1
https://launchpad.net/ubuntu/+source/mysql-5.1/5.1.63-0ubuntu0.11.04.1
https://launchpad.net/ubuntu/+source/mysql-dfsg-5.1/5.1.63-0ubuntu0.10.04.1
https://launchpad.net/ubuntu/+source/mysql-dfsg-5.0/5.0.96-0ubuntu3



--ÙJ2Wsl/hi+uNnGbppLdn
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part
Content-Transfer-Encoding: 7bit

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iQIcBAABCgAGBQJP1mgdAAoJEGVp2FWnRL6ToLUP/3zXUeQCE61tSO33oJxLEhZi
9okzXU2DEuw+XEyHVlby7P3So+WvJTo/kuTMmOO2RhFo+GY7weeR0E4OysXhpTYX
ISVQHzTAXTWXYp3CEsCY5zRvhLvh+s7tbglz+T688kfEU2OwedaK6UiiooXgGVQr
e2OZ/34riLuSxYlU/UZnYHrf72mkDY3/0Cup/eYa0FrG4PZO4fbx0Dn0YCOMh5xz
Ikqg7Y5NXsSOz00DejEbheo/WEHV8mpFKY3zTLWaGlx0Ykidoh5nluA4FFlDXR9i
SezgShSCBGNEhpb6ujJQJeLbBN5R9ZPOU54VlO61lZWhQibMOeFUrC2vtMLgV+/2
EffkqiV7AczPWO9P1suPK2iCi8uo0BGMM15AetApIUfUHR7H8n6HbF5s0z808565
S1RPRZEJDn8k7WJka2l/yyRgDbXpLI1P8tOyAxlx4wh5E2oEeO5Ml0H/D44whAp6
MoXdzD0AA/JksZEj6xmNG5XXSNwuOGbl+sAxTKL85RyzYamv7OFTcbhXK+sNnZ5F
JVUOn7h+xk0wCiSVg1On1G8yEgAv3qWa2ON8DdDnmJxPo2RAKaAzs3YXU/pQ65yl
CKSfkHK/rg1obWtpYpOAd+AjelcxWyIiblqAP6mI7ou3YRrTpgsD2YrYc6sS+gHV
1P8eIgf/HPn+a0Jy3sO3
=P+W7
-----END PGP SIGNATURE-----

--=-PJ2Wsl/hi+uNnGbppLdn--



--===============6964890179595402623==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============6964890179595402623==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung