MySQL Patches Security Flaws

By Ed Oswald | Published May 4, 2006, 2:08 PM

Open source database company MySQL issued a security update to address flaws in its product that could open up users to attack. Rated a "moderate risk" vulnerability by FrSIRT, one of the flaws involves a buffer overflow that could allow for code execution, while the other two involve a validation error, and could expose information within system memory.

The issue affects MySQL versions 4.0.26, 4.1.18. 5.0.20 and 5.1.9, as well as prior versions of those major releases. The most recent version, MySQL 5.0, was released last fall and has seen quick adoption among users of the open source database software.

Comments

View comments by with a score of at least

to dammit_i_changed: these particular bugs are as far as i can tell only exploitable if you let someone access your mysql server.
you can set up mysql to only listen to connections from localhost and only accept connections from localhost.
also use a firewall and block the mysql port.

if its something you run on your home pc i wouldn't be too concerned with these bugs.
however upgrading from one 5.0.x release to another is not more complicated than running the setup program, at least on windows platform

and extra props to Stefano Di Paola for finding these bugs

Score: 0

|

Doh just got Apache 2.2.2 all set up with mod_Ssl, php and mysql now this :(

Well done to MySQL for fixing it tho

Score: 0

|

You don't need to change your apache setup. And if you don't give your users direct access to MySQL this is almost impossible to exploit.

But if you are still worried just update MySQL.

Score: 0

|

I know I don't have to change apache again just a pain after having it nicly set up to be upgrading sql already.

Score: 0

|

Gee, maybe you should try Debian

# apt-get update
# apt-get upgrade

and you're all done.

Score: 0

|

Google rolls out real-time search, Near Me Now, extended personalization

Over time, searches from PCs and mobile phones will grow even "more personalized." But what about user privacy and search results that give you "the truth"?

Intel's marriage of CPU and GPU not ready for prime time

Although there will be an Intel component this month that can compute and plot in parallel, Betanews was told today, it won't be based on Project "Larrabee."

An alternative to Research in Motion's enterprise e-mail? There's an app for that

Good Technology today released an iPhone app compatible with its enterprise e-mail solution.

Playing catch-up in 2010: Windows Mobile, BlackBerry, and Symbian

Microsoft, RIM, and Nokia are each working on improved mobile operating systems. But could these efforts add up to too little, too late?

Not the first, not the last, technology predictions for 2010

Carmi Levy | Wide Angle Zoom: The real truth is probably that what went around in 2009, will come around to haunt us next year.

Google Goggles: Hands on with the Shazam of the Real World

Google today unveiled Goggles, its visual search lab for Android devices that identifies objects by sight.

Microsoft: Windows 7 Family Pack wasn't 'pulled,' it just sold out

If you hurry, you may still be able to find the last Family Pack upgrade editions hanging around retail store shelves, but probably not so much online.

Clever iPhone game returns after being bumped over a name dispute

The game's simple concept and multitude of platforms and puzzles manage to pull off a retro, 8-bit style that's reminiscent of an old Atari game given a modern makeover.

Report: Microsoft to randomize Europe's browser screen choices

The fact that "A" is for "Apple" was apparently at the heart of browser vendor objections to Microsoft's alternative to listing IE first.

Will Nokia's plans further alienate American consumers?

A look at Nokia's plans for the coming years does little to shine up the company's increasingly dull image.

Bing bonked by service outage Thursday, Microsoft configured the wrong server

It's always nice to have a backup, but it's even nicer to remember which one is the backup. That's the lesson Bing's admins learned yesterday evening.