89036 2003-01-27 20:18 /122 rader/ EnGarde Secure Linux <security@guardiandigital.com> Importerad: 2003-01-27 20:18 av Brevbäraren Extern mottagare: engarde-security@guardiandigital.com Extern mottagare: bugtraq@securityfocus.com Mottagare: Bugtraq (import) <3281> Ärende: [ESA-20030127-001] MySQL vulnerabilities ------------------------------------------------------------ -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 +------------------------------------------------------------------------+ | EnGarde Secure Linux Security Advisory January 27, 2003 | | http://www.engardelinux.org/ ESA-20030127-001 | | | | Packages: MySQL, MySQL-client, MySQL-shared | | Summary: Several MySQL vulnerabilities. | +------------------------------------------------------------------------+ EnGarde Secure Linux is a secure distribution of Linux that features improved access control, host and network intrusion detection, Web based secure remote management, e-commerce, and integrated open source security tools. OVERVIEW - -------- The updates provided in ESA-20021213-033 missed one critical fix for the COM_TABLE_DUMP vulnerability. This update properly fixes all of the issues addressed in the recent e-matters advisory: http://security.e-matters.de/advisories/042002.html The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2002-1373 to this issue. All users are recommended to upgrade as soon as possible. SOLUTION - -------- Users of the EnGarde Professional edition can use the Guardian Digital Secure Network to update their systems automatically. EnGarde Community users should upgrade to the most recent version as outlined in this advisory. Updates may be obtained from: ftp://ftp.engardelinux.org/pub/engarde/stable/updates/ http://ftp.engardelinux.org/pub/engarde/stable/updates/ Before upgrading the package, the machine must either: a) be booted into a "standard" kernel; or b) have LIDS disabled. To disable LIDS, execute the command: # /sbin/lidsadm -S -- -LIDS_GLOBAL To install the updated package, execute the command: # rpm -Uvh files You must now update the LIDS configuration by executing the command: # /usr/sbin/config_lids.pl To re-enable LIDS (if it was disabled), execute the command: # /sbin/lidsadm -S -- +LIDS_GLOBAL To verify the signatures of the updated packages, execute the command: # rpm -Kv files UPDATED PACKAGES - ---------------- These updated packages are for EnGarde Secure Linux Community Edition. Source Packages: SRPMS/MySQL-3.23.36-1.0.21.src.rpm MD5 Sum: f03fecd9086da6b0f86746dc8bd07c64 Binary Packages: i386/MySQL-3.23.36-1.0.21.i386.rpm MD5 Sum: 36113d7995b6ebf09aabbb1970e9a203 i386/MySQL-client-3.23.36-1.0.21.i386.rpm MD5 Sum: 4a765f412de0ae0f9f5abfb58812c4fe i386/MySQL-shared-3.23.36-1.0.21.i386.rpm MD5 Sum: 7b5b90da33569f3be8be9bb5d2134533 i686/MySQL-3.23.36-1.0.21.i686.rpm MD5 Sum: 9746529dd241a4b5699bcfcd6aef3dad i686/MySQL-client-3.23.36-1.0.21.i686.rpm MD5 Sum: 5758344c20da729834da89070d783033 i686/MySQL-shared-3.23.36-1.0.21.i686.rpm MD5 Sum: 6f31b91accd7f1c195cc5e00c733407c REFERENCES - ---------- Guardian Digital's public key: http://ftp.engardelinux.org/pub/engarde/ENGARDE-GPG-KEY MySQL's Official Web Site: http://www.mysql.com/ Security Contact: security@guardiandigital.com EnGarde Advisories: http://www.engardelinux.org/advisories.html - -------------------------------------------------------------------------- $Id: ESA-20030127-001-mysql,v 1.1 2003/01/27 16:22:43 rwm Exp $ - -------------------------------------------------------------------------- Author: Ryan W. Maple <ryan@guardiandigital.com> Copyright 2003, Guardian Digital, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.6 (GNU/Linux) Comment: For info see http://www.gnupg.org iD8DBQE+NWFRHD5cqd57fu0RAoh6AJ99xmvmqmKV+yvPvlFBWF78/vYoSACfS7+L XlYH6HhtYZz2G8ElhqyNJ2g= =UONy -----END PGP SIGNATURE----- (89036) /EnGarde Secure Linux <security@guardiandigital.com>/(Ombruten)