mysql-dfsg-5.0 5.0.38-0ubuntu1.4 source package in Ubuntu

Changelog

mysql-dfsg-5.0 (5.0.38-0ubuntu1.4) feisty-security; urgency=low

  * no change build for -security upload

mysql-dfsg-5.0 (5.0.38-0ubuntu1.3) feisty-proposed; urgency=low

  * SECURITY UPDATE: buffer overflow via ProcessOldClientHello() in
    handshake.cpp and input_buffer& operator>> in yassl_imp.cpp
  * SECURITY UPDATE: buffer overread in HASHwithTransform::Update in hash.cpp
  * debian/patches/97_SECURITY_CVE-2008-0226_0227.dpatch: properly verify
    length of input (LP: #186978).
  * SECURITY UPDATE: privilege escalation via crafted CREATE SQL SECURITY
    DEFINER VIEW and ALTER VIEW statements
  * debian/patches/98_SECURITY_CVE-2007-6303.dpatch: make sure lex->definer
    is non-NULL in sql_view.cc (LP: #185039)
  * debian/patches/99_view_fix-now.dpatch: update view.test and view.result to
    use a static year instead of now(). These tests are not part of the build
    but helps with qa-regression-testing
  * SECURITY UPDATE: privilege escalation via SQL SECURITY INVOKER stored
    routines
  * debian/patches/100_SECURITY_CVE-2007-2692.dpatch: restore THD::db_access
    when returning from stored routine by performing privilege checks in the
    execution stage rather than the parsing stage. (LP: #172260)
  * References
    CVE-2008-0226
    CVE-2008-0227
    CVE-2007-6303
    CVE-2007-2692
    http://bugs.mysql.com/bug.php?id=27337

 -- Jamie Strandboge <email address hidden>   Wed, 19 Mar 2008 15:17:20 -0400

Upload details

Uploaded by:
Jamie Strandboge
Uploaded to:
Feisty
Original maintainer:
Ubuntu Development Team
Architectures:
any
Section:
misc
Urgency:
Low Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
mysql-dfsg-5.0_5.0.38.orig.tar.gz 15.8 MiB 0940940c2417938c459b937a937db77042263b46755ebc59ad90f6c49df02c39
mysql-dfsg-5.0_5.0.38-0ubuntu1.4.diff.gz 156.8 KiB f9cf8917efef5359f2c0b7adf90c9e4b0441a246d74f9508354e73b54a2ef8bb
mysql-dfsg-5.0_5.0.38-0ubuntu1.4.dsc 1.2 KiB f32ff400eb9daf18f5c17e26b36fc48c125d662ea30fa58c1000c69526075b1c

View changes file

Binary packages built by this source

libmysqlclient15-dev: No summary available for libmysqlclient15-dev in ubuntu feisty.

No description available for libmysqlclient15-dev in ubuntu feisty.

libmysqlclient15off: No summary available for libmysqlclient15off in ubuntu feisty.

No description available for libmysqlclient15off in ubuntu feisty.

mysql-client: No summary available for mysql-client in ubuntu feisty.

No description available for mysql-client in ubuntu feisty.

mysql-client-5.0: No summary available for mysql-client-5.0 in ubuntu feisty.

No description available for mysql-client-5.0 in ubuntu feisty.

mysql-common: No summary available for mysql-common in ubuntu feisty.

No description available for mysql-common in ubuntu feisty.

mysql-server: No summary available for mysql-server in ubuntu feisty.

No description available for mysql-server in ubuntu feisty.

mysql-server-4.1: No summary available for mysql-server-4.1 in ubuntu feisty.

No description available for mysql-server-4.1 in ubuntu feisty.

mysql-server-5.0: No summary available for mysql-server-5.0 in ubuntu feisty.

No description available for mysql-server-5.0 in ubuntu feisty.