-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Wed, 3 Oct 2007 15:18:46 -0400 Source: mysql-dfsg-5.0 Binary: libmysqlclient15-dev mysql-client mysql-client-5.0 mysql-server mysql-server-5.0 mysql-common libmysqlclient15off Architecture: sparc_translations sparc Version: 5.0.24a-9ubuntu2.1 Distribution: edgy-security Urgency: low Maintainer: Ubuntu/sparc Build Daemon Changed-By: Jamie Strandboge Description: libmysqlclient15-dev - mysql database development files libmysqlclient15off - mysql database client library mysql-client-5.0 - mysql database client binaries mysql-server-5.0 - mysql database server binaries Changes: mysql-dfsg-5.0 (5.0.24a-9ubuntu2.1) edgy-security; urgency=low . * SECURITY UPDATE: denial of service via crafted IF clause * debian/patches/97_CVE-2007-2583.dpatch: fix sql/item_cmpfunc.cc to verify res is not NULL * SECURITY UPDATE: privilege escalation * debian/patches/97_CVE-2007-2691.dpatch: fix sql/sql_parse.cc to make sure DROP privileges are required when using RENAME TABLE statements * SECURITY UPDATE: denial of service via crafted authentication request * debian/patches/97_CVE-2007-3780.dpatch: fix sql/sql_parse.cc to not overflow a signed char * SECURITY UPDATE: privilege escalation via views * debian/patches/97_CVE-2007-3782.dpatch: fix sql/sql_prepare.cc and sql/sql_update.cc to properly verify access privileges to external tables * SECURITY UPDATE: warn on startup if root mysql account has a blank password. debian/mysql-server-5.0.mysql.init: supply 'reset-password' and check blank password. Based on work by Soren Hansen. * References CVE-2007-2583 CVE-2007-2691 CVE-2007-3780 CVE-2007-3782 Launchpad #119075 Files: f494d1f1ee05a672d1dbc98797e5b40a 1771480 libs optional libmysqlclient15off_5.0.24a-9ubuntu2.1_sparc.deb ca10a0db660f04ef8dcdb8cafca15ebb 6942742 libdevel optional libmysqlclient15-dev_5.0.24a-9ubuntu2.1_sparc.deb 7a1a2cb0578b2d9f294957dec1025e31 7048314 misc optional mysql-client-5.0_5.0.24a-9ubuntu2.1_sparc.deb 02d905d78fff0c52241d666760652a74 25302728 misc optional mysql-server-5.0_5.0.24a-9ubuntu2.1_sparc.deb 06ec1d082c603546dd354023da9600d7 22676 raw-translations - mysql-dfsg-5.0_5.0.24a-9ubuntu2.1_sparc_translations.tar.gz -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2.2 (GNU/Linux) iD8DBQFHDDH70N0xjzyQZEIRAm7zAJ9xBZWb6vVhTPVS1JiVS5aV573JsACeNOU9 DIaKIoNE2l/03Bihgp50nrU= =bbXP -----END PGP SIGNATURE-----