Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Ubuntu Local Security Checks >> USN109-1 : mysql-dfsg vulnerability


Vulnerability Assessment Details

USN109-1 : mysql-dfsg vulnerability

Vulnerability Assessment Summary
mysql-dfsg vulnerability

Detailed Explanation for this Vulnerability Assessment

Summary :

These remote packages are missing security patches :
- libmysqlclient-dev
- libmysqlclient12
- mysql-client
- mysql-common
- mysql-server


Description :

USN-32-1 fixed a database privilege escalation vulnerability
original
advisory text:

"If a user was granted rights to a database with a name
containing an underscore ("_"), the user also gained the ability to
grant rights to other databases with similar names.
(CVE-2004-0957)"

Recently a corner case was discovered where this vulnerability can
still be exploited, so another update is necessary.

Solution :

Upgrade to :
- libmysqlclient-dev-4.0.20-2ubuntu1.5 (Ubuntu 4.10)
- libmysqlclient12-4.0.20-2ubuntu1.5 (Ubuntu 4.10)
- mysql-client-4.0.20-2ubuntu1.5 (Ubuntu 4.10)
- mysql-common-4.0.20-2ubuntu1.5 (Ubuntu 4.10)
- mysql-server-4.0.20-2ubuntu1.5 (Ubuntu 4.10)



Network Security Threat Level: High


Networks Security ID:

Vulnerability Assessment Copyright: Ubuntu Security Notice (C) 2005 Canonical, Inc. / NASL script (C) 2005 Michel Arboi

Cables, Connectors


IBM OEM DBOA-2720 720MB 2.5

IBM OEM DBOA-2720 720MB 2.5" IDE 44-Pin LAPTOP HARD DRIVE HDD Vintage TESTED

$67.90



OEM IBM Thinkpad Keyboard 46H3846 picture

OEM IBM Thinkpad Keyboard 46H3846

$10.00



VINTAGE OEM IBM Three-Button ScrollPoint Optical USB Mouse (P/N:24P0494)-Grade B picture

VINTAGE OEM IBM Three-Button ScrollPoint Optical USB Mouse (P/N:24P0494)-Grade B

$13.45



OEM IBM Lenovo ThinkPad T20 T21 T22 T23 T24 02K6620 02K6626 picture

OEM IBM Lenovo ThinkPad T20 T21 T22 T23 T24 02K6620 02K6626

$24.99



IBM Model M Keyboard Flipper and Buckling Spring - Set of 5 - Genuine OEM picture

IBM Model M Keyboard Flipper and Buckling Spring - Set of 5 - Genuine OEM

$3.49



IBM DOS 6.1 OEM VERSION 5.25

IBM DOS 6.1 OEM VERSION 5.25" DISKS NEW SEALED

$24.99



IBM Keyboard T440 T440s T440p T431s Backlit 04X0139 OEM picture

IBM Keyboard T440 T440s T440p T431s Backlit 04X0139 OEM

$24.00



OEM Keyboard for IBM Lenovo N100/N200 3000 series 39T7385 BCF-84US 25-007696 picture

OEM Keyboard for IBM Lenovo N100/N200 3000 series 39T7385 BCF-84US 25-007696

$14.50



Lexmark/IBM 6190653 Black Developer (500k Pages), for the Lexmark 3835 printer picture

Lexmark/IBM 6190653 Black Developer (500k Pages), for the Lexmark 3835 printer

$247.98



VINTAGE IBM OEM 810MB 2.5

VINTAGE IBM OEM 810MB 2.5" Laptop Hard Drive HHD DVAA-2810 P/N: 84G3012

$32.20



Discussions

No Discussions have been posted on this vulnerability.