SuSE: mysql < 3.22.30
Summary
-----BEGIN PGP SIGNED MESSAGE-----
______________________________________________________________________________
SuSE Security Announcement
Package: mysql < 3.22.30
Date: Fri, 11 Feb 2000 21:54:49 GMT
Affected SuSE versions: all
Vulnerability Type: remote database access
SuSE default package: no
Other affected systems: all unix systems using mysql < 3.22.30
______________________________________________________________________________
A security hole was discovered in the package mentioned above.
Please update as soon as possible or disable the service if you are using
this software on your SuSE Linux installation(s).
Other Linux distributions or operating systems might be affected as
well, please contact your vendor for information about this issue.
Please note, that that we provide this information on an "as-is" basis only.
There is no warranty whatsoever and no liability for any direct, indirect or
incidental damage arising from this information or the installation of
the update package.
_____________________________________________________________________________
1. Problem Description
A bug in the authentication function of mysql allows anyone who knows
a valid username to successfully authenticate as that users in no more
than 32 tries.
2. Impact
Remote users may gain access to the mysql database data.
3. Solution
Update the package from our FTP server.
Please note that it will take some time until rpms for 6.1 are available,
because the security patch does not work on that tree. As a workaround, you
might try the rpm for SuSE 6.2
______________________________________________________________________________
Please verify these md5 checksums of the updates before installing:
(6.1 updates are not available yet. You might try the 6.2 rpm in the meantime.)
f54f552d0d7137ae9c2fa44968e32e25
ff61bdf78c72bb8906578533581188b5 /6.2/pay1/mysql-3.22.30-4.i386.rpm
7e8415360e52a100ffb759099dbc8f25 /6.3/pay1/mysql-3.22.30-4.i386.rpm
______________________________________________________________________________
You can find updates on our ftp-Server:
for Intel processors for Alpha processors
or try the following web pages for a list of mirrors:
SUSE – Open-Source-Lösungen für Enterprise Server und Cloud | SUSE
Our webpage for patches:
SUSE – Open-Source-Lösungen für Enterprise Server und Cloud | SUSE
Our webpage for security announcements:
SUSE – Open-Source-Lösungen für Enterprise Server und Cloud | SUSE
If you want to report vulnerabilities, please contact
security@suse.de
______________________________________________________________________________
SuSE has got two free security mailing list services to which any
interested party may subscribe:
suse-security@suse.com - moderated and for general/linux/SuSE
security discussions. All SuSE security
announcements are send to this list.
suse-security-announce@suse.com - SuSE's announce-only mailing list.
Only SuSE's security annoucements are sent
to this list.
To subscribe to the list, send a message to:
References