-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Wed, 3 Oct 2007 13:32:38 -0400 Source: mysql-dfsg-5.0 Binary: libmysqlclient15-dev mysql-client mysql-client-5.0 mysql-server mysql-server-4.1 mysql-server-5.0 mysql-common libmysqlclient15off Architecture: powerpc_translations powerpc Version: 5.0.38-0ubuntu1.1 Distribution: feisty-security Urgency: low Maintainer: Ubuntu/powerpc Build Daemon Changed-By: Jamie Strandboge Description: libmysqlclient15-dev - mysql database development files libmysqlclient15off - mysql database client library mysql-client-5.0 - mysql database client binaries mysql-server-4.1 - mysql database server (transitional package) mysql-server-5.0 - mysql database server binaries Changes: mysql-dfsg-5.0 (5.0.38-0ubuntu1.1) feisty-security; urgency=low . * SECURITY UPDATE: denial of service via crafted IF clause * debian/patches/91_CVE-2007-2583.dpatch: fix sql/item_cmpfunc.cc to verify res is not NULL * SECURITY UPDATE: privilege escalation * debian/patches/91_CVE-2007-2691.dpatch: fix sql/sql_parse.cc to make sure DROP privileges are required when using RENAME TABLE statements * SECURITY UPDATE: denial of service via crafted authentication request * debian/patches/91_CVE-2007-3780.dpatch: fix sql/sql_parse.cc to not overflow a signed char * SECURITY UPDATE: privilege escalation via views * debian/patches/91_CVE-2007-3782.dpatch: fix sql/sql_prepare.cc and sql/sql_update.cc to properly verify access privileges to external tables * SECURITY UPDATE: warn on startup if root mysql account has a blank password. debian/mysql-server-5.0.mysql.init: supply 'reset-password' and check for blank password. Based on work by Soren Hansen. * References CVE-2007-2583 CVE-2007-2691 CVE-2007-3780 CVE-2007-3782 Launchpad #119075 Files: aca91e7490a87046aee0df0f339b58aa 33599 raw-translations - mysql-dfsg-5.0_5.0.38-0ubuntu1.1_powerpc_translations.tar.gz 075962f787639cdca6419d6eebfa1324 1918584 libs optional libmysqlclient15off_5.0.38-0ubuntu1.1_powerpc.deb 0380fa4c4a075bd51e574c558533d72a 7653930 libdevel optional libmysqlclient15-dev_5.0.38-0ubuntu1.1_powerpc.deb 02fbc0f2dd01158c776790680c6f9ff2 7912746 misc optional mysql-client-5.0_5.0.38-0ubuntu1.1_powerpc.deb 3aa11532c1bd46ea1d820ba870900a90 26977146 misc optional mysql-server-5.0_5.0.38-0ubuntu1.1_powerpc.deb ad466ed4dec1fd6157c52f4e3b5cb6e5 47858 oldlibs extra mysql-server-4.1_5.0.38-0ubuntu1.1_powerpc.deb Original-Maintainer: Christian Hammers -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2.2 (GNU/Linux) iD8DBQFHDBly0N0xjzyQZEIRAjhbAJ4pip6kXKh3eqLswVOWW4nX0OeLNwCgg/YC UZx/CsRlVlC1P9VdAAz2oXM= =98wD -----END PGP SIGNATURE-----