- Issued:
- 2005-03-28
- Updated:
- 2005-03-28
RHSA-2005:334 - Security Advisory
Synopsis
mysql security update
Type/Severity
Security Advisory: Important
Red Hat Insights patch analysis
Identify and remediate systems affected by this advisory.
Topic
Updated mysql packages that fix several vulnerabilities are now available.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
Description
MySQL is a multi-user, multi-threaded SQL database server.
This update fixes several security risks in the MySQL server.
Stefano Di Paola discovered two bugs in the way MySQL handles user-defined
functions. A user with the ability to create and execute a user defined
function could potentially execute arbitrary code on the MySQL server. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the names CAN-2005-0709 and CAN-2005-0710 to these issues.
Stefano Di Paola also discovered a bug in the way MySQL creates temporary
tables. A local user could create a specially crafted symlink which could
result in the MySQL server overwriting a file which it has write access to.
The Common Vulnerabilities and Exposures project has assigned the name
CAN-2005-0711 to this issue.
All users of the MySQL server are advised to upgrade to these updated
packages, which contain fixes for these issues.
Solution
Before applying this update, make sure that all previously-released
errata relevant to your system have been applied. Use Red Hat
Network to download and update your packages. To launch the Red Hat
Update Agent, use the following command:
up2date
For information on how to install packages manually, refer to the
following Web page for the System Administration or Customization
guide specific to your system:
Affected Products
- Red Hat Enterprise Linux Server 4 x86_64
- Red Hat Enterprise Linux Server 4 ia64
- Red Hat Enterprise Linux Server 4 i386
- Red Hat Enterprise Linux Server 3 x86_64
- Red Hat Enterprise Linux Server 3 ia64
- Red Hat Enterprise Linux Server 3 i386
- Red Hat Enterprise Linux Server 2 ia64
- Red Hat Enterprise Linux Server 2 i386
- Red Hat Enterprise Linux Workstation 4 x86_64
- Red Hat Enterprise Linux Workstation 4 ia64
- Red Hat Enterprise Linux Workstation 4 i386
- Red Hat Enterprise Linux Workstation 3 x86_64
- Red Hat Enterprise Linux Workstation 3 ia64
- Red Hat Enterprise Linux Workstation 3 i386
- Red Hat Enterprise Linux Workstation 2 ia64
- Red Hat Enterprise Linux Workstation 2 i386
- Red Hat Enterprise Linux Desktop 4 x86_64
- Red Hat Enterprise Linux Desktop 4 i386
- Red Hat Enterprise Linux Desktop 3 x86_64
- Red Hat Enterprise Linux Desktop 3 i386
- Red Hat Enterprise Linux for IBM z Systems 4 s390x
- Red Hat Enterprise Linux for IBM z Systems 4 s390
- Red Hat Enterprise Linux for IBM z Systems 3 s390x
- Red Hat Enterprise Linux for IBM z Systems 3 s390
- Red Hat Enterprise Linux for Power, big endian 4 ppc
- Red Hat Enterprise Linux for Power, big endian 3 ppc
Fixes
- BZ - 150868 - CAN-2005-0711 Insecure temporary file creation with CREATE TEMPORARY TABLE
- BZ - 150871 - CAN-2005-0710 MySQL security attacks via user-defined functions in C (CAN-2005-0709)
- BZ - 151051 - CAN-2005-0710 MySQL security attacks via user-defined functions in C (CAN-2005-0709)
- BZ - 152344 - CAN-2005-0711 Insecure temporary file creation with CREATE TEMPORARY TABLE
References
(none)
Red Hat Enterprise Linux Server 4
SRPM | |
---|---|
x86_64 | |
mysql-4.1.10a-1.RHEL4.1.i386.rpm | SHA-256: a1fb1ee0c8fe64982d85503952651132925cec2fc9685fe19f709ea20ebaddd7 |
mysql-4.1.10a-1.RHEL4.1.i386.rpm | SHA-256: a1fb1ee0c8fe64982d85503952651132925cec2fc9685fe19f709ea20ebaddd7 |
mysql-4.1.10a-1.RHEL4.1.x86_64.rpm | SHA-256: 92dd19842e4367a844d02da10830903b0c907c90917184674810ae746aad6167 |
mysql-4.1.10a-1.RHEL4.1.x86_64.rpm | SHA-256: 92dd19842e4367a844d02da10830903b0c907c90917184674810ae746aad6167 |
mysql-bench-4.1.10a-1.RHEL4.1.x86_64.rpm | SHA-256: 5b5043095055567a93708c89306814142b3a750c4df8b813a2eb3b469deb9e81 |
mysql-bench-4.1.10a-1.RHEL4.1.x86_64.rpm | SHA-256: 5b5043095055567a93708c89306814142b3a750c4df8b813a2eb3b469deb9e81 |
mysql-devel-4.1.10a-1.RHEL4.1.x86_64.rpm | SHA-256: 3433d9598651d23a8aeb872bf9504c15aea706cd953bfcd9499ff4e99e067fd8 |
mysql-devel-4.1.10a-1.RHEL4.1.x86_64.rpm | SHA-256: 3433d9598651d23a8aeb872bf9504c15aea706cd953bfcd9499ff4e99e067fd8 |
mysql-server-4.1.10a-1.RHEL4.1.x86_64.rpm | SHA-256: 3e8b08d73cd1a0c8071788a43e2b870e0a51773de56307934ab9e5e6b87ac397 |
mysql-server-4.1.10a-1.RHEL4.1.x86_64.rpm | SHA-256: 3e8b08d73cd1a0c8071788a43e2b870e0a51773de56307934ab9e5e6b87ac397 |
ia64 | |
mysql-4.1.10a-1.RHEL4.1.i386.rpm | SHA-256: a1fb1ee0c8fe64982d85503952651132925cec2fc9685fe19f709ea20ebaddd7 |
mysql-4.1.10a-1.RHEL4.1.i386.rpm | SHA-256: a1fb1ee0c8fe64982d85503952651132925cec2fc9685fe19f709ea20ebaddd7 |
mysql-4.1.10a-1.RHEL4.1.ia64.rpm | SHA-256: 7954348ea5595336ca684b841f7907743c4260460cd79da0df9c7f810fd838d6 |
mysql-4.1.10a-1.RHEL4.1.ia64.rpm | SHA-256: 7954348ea5595336ca684b841f7907743c4260460cd79da0df9c7f810fd838d6 |
mysql-bench-4.1.10a-1.RHEL4.1.ia64.rpm | SHA-256: 23cca538cd9efba8d29f71251799d737625cc6d84faa860e7a3dce4cd8c57d95 |
mysql-bench-4.1.10a-1.RHEL4.1.ia64.rpm | SHA-256: 23cca538cd9efba8d29f71251799d737625cc6d84faa860e7a3dce4cd8c57d95 |
mysql-devel-4.1.10a-1.RHEL4.1.ia64.rpm | SHA-256: 6f9e252607b3a2d9ae6398308bf58f680195c7d4055e4431990a12cf22377f36 |
mysql-devel-4.1.10a-1.RHEL4.1.ia64.rpm | SHA-256: 6f9e252607b3a2d9ae6398308bf58f680195c7d4055e4431990a12cf22377f36 |
mysql-server-4.1.10a-1.RHEL4.1.ia64.rpm | SHA-256: f88e7f9f4246981fceb55fa795986b86bd5f7bde3935bd8fa66306172b72308d |
mysql-server-4.1.10a-1.RHEL4.1.ia64.rpm | SHA-256: f88e7f9f4246981fceb55fa795986b86bd5f7bde3935bd8fa66306172b72308d |
i386 | |
mysql-4.1.10a-1.RHEL4.1.i386.rpm | SHA-256: a1fb1ee0c8fe64982d85503952651132925cec2fc9685fe19f709ea20ebaddd7 |
mysql-4.1.10a-1.RHEL4.1.i386.rpm | SHA-256: a1fb1ee0c8fe64982d85503952651132925cec2fc9685fe19f709ea20ebaddd7 |
mysql-bench-4.1.10a-1.RHEL4.1.i386.rpm | SHA-256: d0d5749de5af9373554e35a4ea0ded0da8ddc71a4a0d76b15c839035cf51b2fc |
mysql-bench-4.1.10a-1.RHEL4.1.i386.rpm | SHA-256: d0d5749de5af9373554e35a4ea0ded0da8ddc71a4a0d76b15c839035cf51b2fc |
mysql-devel-4.1.10a-1.RHEL4.1.i386.rpm | SHA-256: 5945f12aec1d6fe897a27beade049f982c66a46c4a22466afac3842b16bf1814 |
mysql-devel-4.1.10a-1.RHEL4.1.i386.rpm | SHA-256: 5945f12aec1d6fe897a27beade049f982c66a46c4a22466afac3842b16bf1814 |
mysql-server-4.1.10a-1.RHEL4.1.i386.rpm | SHA-256: 1e73dc722ab8d3b525e486eab3ff783e5734c7454fed4abf40d7371c3bc4b3ee |
mysql-server-4.1.10a-1.RHEL4.1.i386.rpm | SHA-256: 1e73dc722ab8d3b525e486eab3ff783e5734c7454fed4abf40d7371c3bc4b3ee |
Red Hat Enterprise Linux Server 3
SRPM | |
---|---|
x86_64 | |
ia64 | |
i386 |
Red Hat Enterprise Linux Server 2
SRPM | |
---|---|
ia64 | |
i386 |
Red Hat Enterprise Linux Workstation 4
SRPM | |
---|---|
x86_64 | |
mysql-4.1.10a-1.RHEL4.1.i386.rpm | SHA-256: a1fb1ee0c8fe64982d85503952651132925cec2fc9685fe19f709ea20ebaddd7 |
mysql-4.1.10a-1.RHEL4.1.x86_64.rpm | SHA-256: 92dd19842e4367a844d02da10830903b0c907c90917184674810ae746aad6167 |
mysql-bench-4.1.10a-1.RHEL4.1.x86_64.rpm | SHA-256: 5b5043095055567a93708c89306814142b3a750c4df8b813a2eb3b469deb9e81 |
mysql-devel-4.1.10a-1.RHEL4.1.x86_64.rpm | SHA-256: 3433d9598651d23a8aeb872bf9504c15aea706cd953bfcd9499ff4e99e067fd8 |
mysql-server-4.1.10a-1.RHEL4.1.x86_64.rpm | SHA-256: 3e8b08d73cd1a0c8071788a43e2b870e0a51773de56307934ab9e5e6b87ac397 |
ia64 | |
mysql-4.1.10a-1.RHEL4.1.i386.rpm | SHA-256: a1fb1ee0c8fe64982d85503952651132925cec2fc9685fe19f709ea20ebaddd7 |
mysql-4.1.10a-1.RHEL4.1.ia64.rpm | SHA-256: 7954348ea5595336ca684b841f7907743c4260460cd79da0df9c7f810fd838d6 |
mysql-bench-4.1.10a-1.RHEL4.1.ia64.rpm | SHA-256: 23cca538cd9efba8d29f71251799d737625cc6d84faa860e7a3dce4cd8c57d95 |
mysql-devel-4.1.10a-1.RHEL4.1.ia64.rpm | SHA-256: 6f9e252607b3a2d9ae6398308bf58f680195c7d4055e4431990a12cf22377f36 |
mysql-server-4.1.10a-1.RHEL4.1.ia64.rpm | SHA-256: f88e7f9f4246981fceb55fa795986b86bd5f7bde3935bd8fa66306172b72308d |
i386 | |
mysql-4.1.10a-1.RHEL4.1.i386.rpm | SHA-256: a1fb1ee0c8fe64982d85503952651132925cec2fc9685fe19f709ea20ebaddd7 |
mysql-bench-4.1.10a-1.RHEL4.1.i386.rpm | SHA-256: d0d5749de5af9373554e35a4ea0ded0da8ddc71a4a0d76b15c839035cf51b2fc |
mysql-devel-4.1.10a-1.RHEL4.1.i386.rpm | SHA-256: 5945f12aec1d6fe897a27beade049f982c66a46c4a22466afac3842b16bf1814 |
mysql-server-4.1.10a-1.RHEL4.1.i386.rpm | SHA-256: 1e73dc722ab8d3b525e486eab3ff783e5734c7454fed4abf40d7371c3bc4b3ee |
Red Hat Enterprise Linux Workstation 3
SRPM | |
---|---|
x86_64 | |
ia64 | |
i386 |
Red Hat Enterprise Linux Workstation 2
SRPM | |
---|---|
ia64 | |
i386 |
Red Hat Enterprise Linux Desktop 4
SRPM | |
---|---|
x86_64 | |
mysql-4.1.10a-1.RHEL4.1.i386.rpm | SHA-256: a1fb1ee0c8fe64982d85503952651132925cec2fc9685fe19f709ea20ebaddd7 |
mysql-4.1.10a-1.RHEL4.1.x86_64.rpm | SHA-256: 92dd19842e4367a844d02da10830903b0c907c90917184674810ae746aad6167 |
mysql-bench-4.1.10a-1.RHEL4.1.x86_64.rpm | SHA-256: 5b5043095055567a93708c89306814142b3a750c4df8b813a2eb3b469deb9e81 |
mysql-devel-4.1.10a-1.RHEL4.1.x86_64.rpm | SHA-256: 3433d9598651d23a8aeb872bf9504c15aea706cd953bfcd9499ff4e99e067fd8 |
mysql-server-4.1.10a-1.RHEL4.1.x86_64.rpm | SHA-256: 3e8b08d73cd1a0c8071788a43e2b870e0a51773de56307934ab9e5e6b87ac397 |
i386 | |
mysql-4.1.10a-1.RHEL4.1.i386.rpm | SHA-256: a1fb1ee0c8fe64982d85503952651132925cec2fc9685fe19f709ea20ebaddd7 |
mysql-bench-4.1.10a-1.RHEL4.1.i386.rpm | SHA-256: d0d5749de5af9373554e35a4ea0ded0da8ddc71a4a0d76b15c839035cf51b2fc |
mysql-devel-4.1.10a-1.RHEL4.1.i386.rpm | SHA-256: 5945f12aec1d6fe897a27beade049f982c66a46c4a22466afac3842b16bf1814 |
mysql-server-4.1.10a-1.RHEL4.1.i386.rpm | SHA-256: 1e73dc722ab8d3b525e486eab3ff783e5734c7454fed4abf40d7371c3bc4b3ee |
Red Hat Enterprise Linux Desktop 3
SRPM | |
---|---|
x86_64 | |
i386 |
Red Hat Enterprise Linux for IBM z Systems 4
SRPM | |
---|---|
s390x | |
mysql-4.1.10a-1.RHEL4.1.s390.rpm | SHA-256: 30224d9c4380be981e97353c70e355e7dd3d7393154d00e63e543c0fbcba606b |
mysql-4.1.10a-1.RHEL4.1.s390x.rpm | SHA-256: 3c9e2844801a3d4700935d8a14ea52a30946e6f48519cfbecbc9082f931b434b |
mysql-bench-4.1.10a-1.RHEL4.1.s390x.rpm | SHA-256: e06f59d542525ee9dbeced4972c6b3ce6bb6b1f77267d11db532801bc455d23c |
mysql-devel-4.1.10a-1.RHEL4.1.s390x.rpm | SHA-256: 6733011ef28773f6948c001470eba5b0480680301cc6d49732882b9e9d73be74 |
mysql-server-4.1.10a-1.RHEL4.1.s390x.rpm | SHA-256: fef7308ac3cf16fcd1363242adf860398df5126868005d14f3e7e2b7fcd83b53 |
s390 | |
mysql-4.1.10a-1.RHEL4.1.s390.rpm | SHA-256: 30224d9c4380be981e97353c70e355e7dd3d7393154d00e63e543c0fbcba606b |
mysql-bench-4.1.10a-1.RHEL4.1.s390.rpm | SHA-256: 1a730522bd17ac30164469ae4a48beca60a16ed730020f665fd1128c23ea8a69 |
mysql-devel-4.1.10a-1.RHEL4.1.s390.rpm | SHA-256: 5bbfe67d2e153534bc3acf06ffdbae4a8ac456ab248b59442c8a9824fd4c0b8c |
mysql-server-4.1.10a-1.RHEL4.1.s390.rpm | SHA-256: cf4e864ba07e587e757fb32bb7ab11e880974feb96e746a5a9424eb7565782b6 |
Red Hat Enterprise Linux for IBM z Systems 3
SRPM | |
---|---|
s390x | |
s390 |
Red Hat Enterprise Linux for Power, big endian 4
SRPM | |
---|---|
ppc | |
mysql-4.1.10a-1.RHEL4.1.ppc.rpm | SHA-256: 84f35e44289bf024dde73557defcd1b1c20486fa5fbf87030194744caa4ce31d |
mysql-4.1.10a-1.RHEL4.1.ppc64.rpm | SHA-256: 8f21e9dbd8448b5edcd196fab2f536bb07aea34b65d26fe492221c92a03a0136 |
mysql-bench-4.1.10a-1.RHEL4.1.ppc.rpm | SHA-256: 39bf8df8e926f7ccf4deee60aa2f2b4764e3c7587f7e5b2a22d437c442ebe9d4 |
mysql-devel-4.1.10a-1.RHEL4.1.ppc.rpm | SHA-256: fd4b60b16484f0065d1e090dda315607b457b48eec6b83853fe4f14ac4387870 |
mysql-server-4.1.10a-1.RHEL4.1.ppc.rpm | SHA-256: 723eed212696804a01bb67f2be1e2d0cc6a1b3411fd32a02188202c8769671cb |
Red Hat Enterprise Linux for Power, big endian 3
SRPM | |
---|---|
ppc |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.