mysql
171
(
BZ#475549
1223
)
Users are advised to upgrade to these updated module-init-tools packages, which resolve these
issues.
1.148. mysql
1.148.1. RHSA-2009:1289: Moderate security and bug fix update
MySQL is a multi-user, multi-threaded SQL database server. It consists of the MySQL server daemon
(mysqld) and many client programs and libraries.
MySQL did not correctly check directories used as arguments for the DATA DIRECTORY and
INDEX DIRECTORY directives. Using this flaw, an authenticated attacker could elevate their access
privileges to tables created by other database users. Note: This attack does not work on existing
tables. An attacker can only elevate their access to another user's tables as the tables are created.
As well, the names of these created tables need to be predicted correctly for this attack to succeed.
(
CVE-2008-2079
1224
)
A flaw was found in the way MySQL handles an empty bit-string literal. A remote, authenticated
attacker could crash the MySQL server daemon (mysqld) if they used an empty bit-string literal in an
SQL statement. This issue only caused a temporary denial of service, as the MySQL daemon was
automatically restarted after the crash. (
CVE-2008-3963
1225
)
An insufficient HTML entities quoting flaw was found in the mysql command line client's HTML output
mode. If an attacker was able to inject arbitrary HTML tags into data stored in a MySQL database,
which was later retrieved using the mysql command line client and its HTML output mode, they could
perform a cross-site scripting (XSS) attack against victims viewing the HTML output in a web browser.
(
CVE-2008-4456
1226
)
Multiple format string flaws were found in the way the MySQL server logs user commands when
creating and deleting databases. A remote, authenticated attacker with permissions to CREATE
and DROP databases could use these flaws to formulate a specifically-crafted SQL command
that would cause a temporary denial of service (open connections to mysqld are terminated).
(
CVE-2009-2446
1227
)
Note
To exploit the
CVE-2009-2446
1228
flaws, the general query log (the mysqld "--log"
command line option or the "log" option in "/etc/my.cnf") must be enabled. This logging is
not enabled by default.
This update also fixes multiple bugs:
• an error in the mysqld init script caused the MySQL service to not wait correctly if the socket file
specified in /etc/my.cnf was anything other than the default. This caused MySQL to return an
1224
https://www.redhat.com/security/data/cve/CVE-2008-2079.html
1225
https://www.redhat.com/security/data/cve/CVE-2008-3963.html
1226
https://www.redhat.com/security/data/cve/CVE-2008-4456.html
1227
https://www.redhat.com/security/data/cve/CVE-2009-2446.html
Summary of Contents for ENTERPRISE 5.4 RELEASE NOTES
Page 1: ...Red Hat Enterprise Linux 5 4 Technical Notes Every Change to Every Package ...
Page 18: ...xviii ...
Page 306: ...288 ...
Page 464: ...446 ...
Page 466: ...448 ...