-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Tue, 2 Oct 2007 14:46:02 -0400 Source: mysql-dfsg-5.0 Binary: libmysqlclient15-dev mysql-client mysql-client-5.0 mysql-server mysql-server-5.0 mysql-common libmysqlclient15off Architecture: powerpc_translations powerpc Version: 5.0.22-0ubuntu6.06.5 Distribution: dapper-security Urgency: low Maintainer: Ubuntu/powerpc Build Daemon Changed-By: Jamie Strandboge Description: libmysqlclient15-dev - mysql database development files libmysqlclient15off - mysql database client library mysql-client-5.0 - mysql database client binaries mysql-server-5.0 - mysql database server binaries Changes: mysql-dfsg-5.0 (5.0.22-0ubuntu6.06.5) dapper-security; urgency=low . * SECURITY UPDATE: denial of service via crafted IF clause * debian/patches/SECURITY_CVE-2007-2583.dpatch: fix sql/item_cmpfunc.cc to verify res is not NULL * SECURITY UPDATE: privilege escalation * debian/patches/SECURITY_CVE-2007-2691.dpatch: fix sql/sql_parse.cc to make sure DROP privileges are required when using RENAME TABLE statements * SECURITY UPDATE: denial of service via crafted authentication request * debian/patches/SECURITY_CVE-2007-3780.dpatch: fix sql/sql_parse.cc to not overflow a signed char * SECURITY UPDATE: privilege escalation via views * debian/patches/SECURITY_CVE-2007-3782.dpatch: fix sql/sql_prepare.cc and sql/sql_update.cc to properly verify access privileges to external tables * SECURITY UPDATE: warn on startup if root mysql account has a blank password. debian/mysql-server-5.0.mysql.init: supply 'reset-password' and check for blank password. Based on work by Soren Hansen. * References CVE-2007-2583 CVE-2007-2691 CVE-2007-3780 CVE-2007-3782 Launchpad #119075 Files: a66d382783bedbf4c2ad57f1b763d4a2 1462642 libs optional libmysqlclient15off_5.0.22-0ubuntu6.06.5_powerpc.deb 4f5f003ab2fb4e801c7b55c9e04e1fb0 6883652 libdevel optional libmysqlclient15-dev_5.0.22-0ubuntu6.06.5_powerpc.deb 00d98f99e72e2300ca62fa60f6197502 6940358 misc optional mysql-client-5.0_5.0.22-0ubuntu6.06.5_powerpc.deb 07d7feaed935ee0542589c35508b20d4 22704382 misc optional mysql-server-5.0_5.0.22-0ubuntu6.06.5_powerpc.deb ad714dd897df1312d65d158043c09d7f 22364 raw-translations - mysql-dfsg-5.0_5.0.22-0ubuntu6.06.5_powerpc_translations.tar.gz -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2.2 (GNU/Linux) iD8DBQFHDU9k0N0xjzyQZEIRAlwwAKCLzUy45snN2UAtbmooH7feVUu1GwCfSYZR z1ICv9kCj55KVXGUcMgGjeY= =b70f -----END PGP SIGNATURE-----