SciLinux: CVE-2007-5969 mysql SL5.x, SL4.x i386/x86_64
Summary
Date: Wed, 19 Dec 2007 15:19:58 -0600Reply-To: Troy DawsonSender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for mysql on SL5.x, SL4.x i386/x86_64Comments: To: "scientific-linux-errata@fnal.gov" Synopsis: Important: mysql security updateIssue date: 2007-12-18CVE Names: CVE-2007-5969 CVE-2007-5925A flaw was found in a way MySQL handled symbolic links when database tableswere created with explicit "DATA" and "INDEX DIRECTORY" options. Anauthenticated user could create a table that would overwrite tables inother databases, causing destruction of data or allowing the user toelevate privileges. (CVE-2007-5969)A flaw was found in a way MySQL's InnoDB engine handled spatial indexes. Anauthenticated user could create a table with spatial indexes, which are notsupported by the InnoDB engine, that would cause the mysql daemon to crashwhen used. This issue only causes a temporary denial of service, as themysql daemon will be automatically restarted after the crash.(CVE-2007-5925)SL 4.x SRPMS:mysql-4.1.20-3.RHEL4.1.el4_6.1.src.rpm i386:mysql-4.1.20-3.RHEL4.1.el4_6.1.i386.rpmmysql-bench-4.1.20-3.RHEL4.1.el4_6.1.i386.rpmmysql-devel-4.1.20-3.RHEL4.1.el4_6.1.i386.rpmmysql-server-4.1.20-3.RHEL4.1.el4_6.1.i386.rpm x86_64:mysql-4.1.20-3.RHEL4.1.el4.1.x86_64.rpmmysql-4.1.20-3.RHEL4.1.el4_6.1.i386.rpmmysql-bench-4.1.20-3.RHEL4.1.el4.1.x86_64.rpmmysql-devel-4.1.20-3.RHEL4.1.el4.1.x86_64.rpmmysql-devel-4.1.20-3.RHEL4.1.el4_6.1.i386.rpmmysql-server-4.1.20-3.RHEL4.1.el4.1.x86_64.rpmSL 5.x SRPMS:mysql-5.0.22-2.2.el5_1.1.src.rpm i386:mysql-5.0.22-2.2.el5_1.1.i386.rpmmysql-bench-5.0.22-2.2.el5_1.1.i386.rpmmysql-devel-5.0.22-2.2.el5_1.1.i386.rpmmysql-server-5.0.22-2.2.el5_1.1.i386.rpmmysql-test-5.0.22-2.2.el5_1.1.i386.rpm x86_64:mysql-5.0.22-2.2.el5_1.1.i386.rpmmysql-5.0.22-2.2.el5_1.1.x86_64.rpmmysql-bench-5.0.22-2.2.el5_1.1.x86_64.rpmmysql-devel-5.0.22-2.2.el5_1.1.i386.rpmmysql-devel-5.0.22-2.2.el5_1.1.x86_64.rpmmysql-server-5.0.22-2.2.el5_1.1.x86_64.rpmmysql-test-5.0.22-2.2.el5_1.1.x86_64.rpm-Connie Sieh-Troy Dawson