Link [ pkgsrc | NetBSD | pkgsrc git mirror | PR fulltext-search | netbsd commit viewer ]


   
        usage: [branch:branch] [user:user] [path[@revision]] keyword [... [-excludekeyword [...]]] (e.g. branch:MAIN pkgtools/pkg)




switch to index mode

recent branches: MAIN (4h)  pkgsrc-2024Q1 (10d)  pkgsrc-2023Q4 (57d)  pkgsrc-2023Q2 (90d)  pkgsrc-2023Q3 (169d) 

2024-05-28 08:32:55 UTC Now

2010-06-06 11:32:35 UTC pkgsrc-2010Q1 commitmail json YAML

Pullup ticket 3139 - requested by taca
security update

Revisions pulled up:
- pkgsrc/databases/mysql5-client/Makefile.common 1.39
- pkgsrc/databases/mysql5-client/buildlink3.mk 1.16
- pkgsrc/databases/mysql5-client/distinfo 1.29
- pkgsrc/databases/mysql5-server/distinfo 1.25

  -------------------------------------------------------------------------
  Module Name:    pkgsrc
  Committed By:  taca
  Date:          Wed Jun  2 13:34:45 UTC 2010

  Modified Files:
          pkgsrc/databases/mysql5-client: Makefile.common buildlink3.mk distinfo
          pkgsrc/databases/mysql5-server: distinfo

  Log Message:
  Update mysql5-{client,server} package to 5.0.91.

  For full changes, refer http://dev.mysql.com/doc/refman/5.0/en/news-5-0-91.html.

  Here is security related changes.

  * Security Fix: The server failed to check the table name argument of
    a COM_FIELD_LIST command packet for validity and compliance to
    acceptable table name standards. This could be exploited to bypass
    almost all forms of checks for privileges and table-level grants by
    providing a specially crafted table name argument to COM_FIELD_LIST.

    In MySQL 5.0 and above, this allowed an authenticated user with
    SELECT privileges on one table to obtain the field definitions of
    any table in all other databases and potentially of other MySQL
    instances accessible from the server's file system.

    Additionally, for MySQL version 5.1 and above, an authenticated user
    with DELETE or SELECT privileges on one table could delete or read
    content from any other table in all databases on this server, and
    potentially of other MySQL instances accessible from the server's
    file system. (Bug#53371, CVE-2010-1848)

  * Security Fix: The server was susceptible to a buffer-overflow attack
    due to a failure to perform bounds checking on the table name
    argument of a COM_FIELD_LIST command packet. By sending long data
    for the table name, a buffer is overflown, which could be exploited
    by an authenticated user to inject malicious code. (Bug#53237,
    CVE-2010-1850)

  * Security Fix: The server could be tricked into reading packets
    indefinitely if it received a packet larger than the maximum size of
    one packet. (Bug#50974, CVE-2010-1849)

  To generate a diff of this commit:
  cvs rdiff -u -r1.38 -r1.39 pkgsrc/databases/mysql5-client/Makefile.common
  cvs rdiff -u -r1.15 -r1.16 pkgsrc/databases/mysql5-client/buildlink3.mk
  cvs rdiff -u -r1.28 -r1.29 pkgsrc/databases/mysql5-client/distinfo
  cvs rdiff -u -r1.24 -r1.25 pkgsrc/databases/mysql5-server/distinfo

(spz)