Executive Summary
Summary | |
---|---|
Title | New mysql-dfsg-5.0 packages fix multiple vulnerabilities |
Informations | |||
---|---|---|---|
Name | DSA-1783 | First vendor Publication | 2009-04-29 |
Vendor | Debian | Last vendor Modification | 2009-04-29 |
Severity (Vendor) | N/A | Revision | 1 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:S/C:N/I:N/A:P) | |||
---|---|---|---|
Cvss Base Score | 4 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Low |
Cvss Expoit Score | 8 | Authentication | Requires single instance |
Calculate full CVSS 2.0 Vectors scores |
Detail
Multiple vulnerabilities have been identified affecting MySQL, a relational database server, and its associated interactive client application. The Common Vulnerabilities and Exposures project identifies the following two problems: CVE-2008-3963 Kay Roepke reported that the MySQL server would not properly handle an empty bit-string literal in an SQL statement, allowing an authenticated remote attacker to cause a denial of service (a crash) in mysqld. This issue affects the oldstable distribution (etch), but not the stable distribution (lenny). CVE-2008-4456 Thomas Henlich reported that the MySQL commandline client application did not encode HTML special characters when run in HTML output mode (that is, "mysql --html ..."). This could potentially lead to cross-site scripting or unintended script privilege escalation if the resulting output is viewed in a browser or incorporated into a web site. For the old stable distribution (etch), these problems have been fixed in version 5.0.32-7etch10. For the stable distribution (lenny), these problems have been fixed in version 5.0.51a-24+lenny1. We recommend that you upgrade your mysql-dfsg-5.0 packages. |
Original Source
Url : http://www.debian.org/security/2009/dsa-1783 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
50 % | CWE-134 | Uncontrolled Format String (CWE/SANS Top 25) |
50 % | CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') (CWE/SANS Top 25) |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:10521 | |||
Oval ID: | oval:org.mitre.oval:def:10521 | ||
Title: | MySQL 5.0 before 5.0.66, 5.1 before 5.1.26, and 6.0 before 6.0.6 does not properly handle a b'' (b single-quote single-quote) token, aka an empty bit-string literal, which allows remote attackers to cause a denial of service (daemon crash) by using this token in a SQL statement. | ||
Description: | MySQL 5.0 before 5.0.66, 5.1 before 5.1.26, and 6.0 before 6.0.6 does not properly handle a b'' (b single-quote single-quote) token, aka an empty bit-string literal, which allows remote attackers to cause a denial of service (daemon crash) by using this token in a SQL statement. | ||
Family: | unix | Class: | vulnerability |
Reference(s): | CVE-2008-3963 | Version: | 5 |
Platform(s): | Red Hat Enterprise Linux 5 CentOS Linux 5 Oracle Linux 5 | Product(s): | |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:11456 | |||
Oval ID: | oval:org.mitre.oval:def:11456 | ||
Title: | Cross-site scripting (XSS) vulnerability in the command-line client in MySQL 5.0.26 through 5.0.45, and other versions including versions later than 5.0.45, when the --html option is enabled, allows attackers to inject arbitrary web script or HTML by placing it in a database cell, which might be accessed by this client when composing an HTML document. NOTE: as of 20081031, the issue has not been fixed in MySQL 5.0.67. | ||
Description: | Cross-site scripting (XSS) vulnerability in the command-line client in MySQL 5.0.26 through 5.0.45, and other versions including versions later than 5.0.45, when the --html option is enabled, allows attackers to inject arbitrary web script or HTML by placing it in a database cell, which might be accessed by this client when composing an HTML document. NOTE: as of 20081031, the issue has not been fixed in MySQL 5.0.67. | ||
Family: | unix | Class: | vulnerability |
Reference(s): | CVE-2008-4456 | Version: | 5 |
Platform(s): | Red Hat Enterprise Linux 4 CentOS Linux 4 Oracle Linux 4 Red Hat Enterprise Linux 5 CentOS Linux 5 Oracle Linux 5 | Product(s): | |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:16963 | |||
Oval ID: | oval:org.mitre.oval:def:16963 | ||
Title: | USN-671-1 -- mysql-dfsg-5.0 vulnerabilities | ||
Description: | It was discovered that MySQL could be made to overwrite existing table files in the data directory. | ||
Family: | unix | Class: | patch |
Reference(s): | USN-671-1 CVE-2008-2079 CVE-2008-4097 CVE-2008-4098 CVE-2008-3963 | Version: | 7 |
Platform(s): | Ubuntu 6.06 Ubuntu 7.10 Ubuntu 8.04 | Product(s): | mysql-dfsg-5.0 |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:20178 | |||
Oval ID: | oval:org.mitre.oval:def:20178 | ||
Title: | DSA-1783-1 mysql-dfsg-5.0 - several vulnerabilities | ||
Description: | Multiple vulnerabilities have been identified affecting MySQL, a relational database server, and its associated interactive client application. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-1783-1 CVE-2008-3963 CVE-2008-4456 | Version: | 5 |
Platform(s): | Debian GNU/Linux 4.0 Debian GNU/Linux 5.0 | Product(s): | mysql-dfsg-5.0 |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:7877 | |||
Oval ID: | oval:org.mitre.oval:def:7877 | ||
Title: | DSA-1783 mysql-dfsg-5.0 -- multiple vulnerabilities | ||
Description: | Multiple vulnerabilities have been identified affecting MySQL, a relational database server, and its associated interactive client application. The Common Vulnerabilities and Exposures project identifies the following two problems: Kay Roepke reported that the MySQL server would not properly handle an empty bit-string literal in an SQL statement, allowing an authenticated remote attacker to cause a denial of service (a crash) in mysqld. This issue affects the oldstable distribution (etch), but not the stable distribution (lenny). Thomas Henlich reported that the MySQL commandline client application did not encode HTML special characters when run in HTML output mode (that is, "mysql --html ..."). This could potentially lead to cross-site scripting or unintended script privilege escalation if the resulting output is viewed in a browser or incorporated into a web site. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-1783 CVE-2008-3963 CVE-2008-4456 | Version: | 3 |
Platform(s): | Debian GNU/Linux 5.0 Debian GNU/Linux 4.0 | Product(s): | mysql-dfsg-5.0 |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2012-03-16 | Name : Ubuntu Update for mysql-5.1 USN-1397-1 File : nvt/gb_ubuntu_USN_1397_1.nasl |
2012-02-12 | Name : Gentoo Security Advisory GLSA 201201-02 (MySQL) File : nvt/glsa_201201_02.nasl |
2011-08-09 | Name : CentOS Update for mysql CESA-2009:1289 centos5 i386 File : nvt/gb_CESA-2009_1289_mysql_centos5_i386.nasl |
2010-05-12 | Name : Mac OS X 10.6.3 Update / Mac OS X Security Update 2010-002 File : nvt/macosx_upd_10_6_3_secupd_2010-002.nasl |
2010-02-19 | Name : CentOS Update for mysql CESA-2010:0110 centos4 i386 File : nvt/gb_CESA-2010_0110_mysql_centos4_i386.nasl |
2010-02-19 | Name : RedHat Update for mysql RHSA-2010:0110-01 File : nvt/gb_RHSA-2010_0110-01_mysql.nasl |
2010-02-15 | Name : Ubuntu Update for MySQL vulnerabilities USN-897-1 File : nvt/gb_ubuntu_USN_897_1.nasl |
2009-12-10 | Name : Mandriva Security Advisory MDVSA-2009:326 (mysql) File : nvt/mdksa_2009_326.nasl |
2009-10-13 | Name : SLES10: Security update for MySQL File : nvt/sles10_mysql.nasl |
2009-10-13 | Name : SLES10: Security update for MySQL File : nvt/sles10_mysql0.nasl |
2009-10-11 | Name : SLES11: Security update for MySQL File : nvt/sles11_libmysqlclient1.nasl |
2009-10-10 | Name : SLES9: Security update for MySQL File : nvt/sles9p5056120.nasl |
2009-09-28 | Name : RedHat Security Advisory RHSA-2009:1461 File : nvt/RHSA_2009_1461.nasl |
2009-09-21 | Name : CentOS Security Advisory CESA-2009:1289 (mysql) File : nvt/ovcesa2009_1289.nasl |
2009-09-09 | Name : SuSE Security Summary SUSE-SR:2009:014 File : nvt/suse_sr_2009_014.nasl |
2009-09-09 | Name : RedHat Security Advisory RHSA-2009:1289 File : nvt/RHSA_2009_1289.nasl |
2009-06-05 | Name : Ubuntu USN-763-1 (xine-lib) File : nvt/ubuntu_763_1.nasl |
2009-06-05 | Name : RedHat Security Advisory RHSA-2009:1067 File : nvt/RHSA_2009_1067.nasl |
2009-04-28 | Name : Mandrake Security Advisory MDVSA-2009:094 (mysql) File : nvt/mdksa_2009_094.nasl |
2009-03-23 | Name : Ubuntu Update for mysql-dfsg-5.0 vulnerabilities USN-671-1 File : nvt/gb_ubuntu_USN_671_1.nasl |
2009-01-20 | Name : SuSE Security Summary SUSE-SR:2009:001 (OpenSuSE 11.1) File : nvt/suse_sr_2009_001.nasl |
2009-01-20 | Name : SuSE Security Summary SUSE-SR:2009:001 (OpenSuSE 11.0) File : nvt/suse_sr_2009_001a.nasl |
2009-01-20 | Name : SuSE Security Summary SUSE-SR:2009:001 (OpenSuSE 10.3) File : nvt/suse_sr_2009_001b.nasl |
2009-01-13 | Name : FreeBSD Ports: mysql-server File : nvt/freebsd_mysql-server16.nasl |
2008-10-03 | Name : FreeBSD Ports: mysql-client File : nvt/freebsd_mysql-client0.nasl |
2008-09-25 | Name : MySQL Empty Bit-String Literal Denial of Service Vulnerability File : nvt/secpod_mysql_dos_vuln_900221.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
48710 | MySQL Command Line Client HTML Output XSS |
48021 | MySQL Empty Bit-String Literal Token SQL Statement DoS |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2013-07-12 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2010-0110.nasl - Type : ACT_GATHER_INFO |
2013-01-24 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2009-1289.nasl - Type : ACT_GATHER_INFO |
2012-08-01 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20100216_mysql_on_SL4_x.nasl - Type : ACT_GATHER_INFO |
2012-08-01 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20090902_mysql_on_SL5_x.nasl - Type : ACT_GATHER_INFO |
2012-03-13 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-1397-1.nasl - Type : ACT_GATHER_INFO |
2012-01-16 | Name : A remote database client have a cross-site scripting vulnerability. File : mysql_6_0_14_XSS.nasl - Type : ACT_GATHER_INFO |
2012-01-06 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201201-02.nasl - Type : ACT_GATHER_INFO |
2010-03-29 | Name : The remote host is missing a Mac OS X update that fixes various security issues. File : macosx_10_6_3.nasl - Type : ACT_GATHER_INFO |
2010-02-18 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2010-0110.nasl - Type : ACT_GATHER_INFO |
2010-02-17 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2010-0110.nasl - Type : ACT_GATHER_INFO |
2010-02-11 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-897-1.nasl - Type : ACT_GATHER_INFO |
2010-01-06 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2009-1289.nasl - Type : ACT_GATHER_INFO |
2009-12-08 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2009-326.nasl - Type : ACT_GATHER_INFO |
2009-10-06 | Name : The remote openSUSE host is missing a security update. File : suse_libmysqlclient-devel-6360.nasl - Type : ACT_GATHER_INFO |
2009-09-24 | Name : The remote SuSE 10 host is missing a security-related patch. File : suse_mysql-6446.nasl - Type : ACT_GATHER_INFO |
2009-09-24 | Name : The remote SuSE 11 host is missing one or more security updates. File : suse_11_libmysqlclient-devel-090716.nasl - Type : ACT_GATHER_INFO |
2009-09-24 | Name : The remote SuSE 9 host is missing a security-related patch. File : suse9_12456.nasl - Type : ACT_GATHER_INFO |
2009-08-27 | Name : The remote openSUSE host is missing a security update. File : suse_11_0_libmysqlclient-devel-090716.nasl - Type : ACT_GATHER_INFO |
2009-08-27 | Name : The remote openSUSE host is missing a security update. File : suse_11_1_libmysqlclient-devel-090716.nasl - Type : ACT_GATHER_INFO |
2009-07-21 | Name : The remote openSUSE host is missing a security update. File : suse_11_0_libmysqlclient-devel-080919.nasl - Type : ACT_GATHER_INFO |
2009-04-30 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-1783.nasl - Type : ACT_GATHER_INFO |
2009-04-23 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2009-094.nasl - Type : ACT_GATHER_INFO |
2009-04-23 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-671-1.nasl - Type : ACT_GATHER_INFO |
2009-01-12 | Name : The remote FreeBSD host is missing one or more security-related updates. File : freebsd_pkg_66a770b4e00811dda7650030843d3802.nasl - Type : ACT_GATHER_INFO |
2008-12-21 | Name : The remote openSUSE host is missing a security update. File : suse_libmysqlclient-devel-5619.nasl - Type : ACT_GATHER_INFO |
2008-12-01 | Name : The remote openSUSE host is missing a security update. File : suse_mysql-5613.nasl - Type : ACT_GATHER_INFO |
2008-11-13 | Name : The remote SuSE 10 host is missing a security-related patch. File : suse_mysql-5618.nasl - Type : ACT_GATHER_INFO |
2008-10-13 | Name : The remote FreeBSD host is missing one or more security-related updates. File : freebsd_pkg_4775c8078f3011dd821f001cc0377035.nasl - Type : ACT_GATHER_INFO |
2008-09-11 | Name : The remote database server is susceptible to a denial of service attack. File : mysql_5_1_26.nasl - Type : ACT_GATHER_INFO |
2008-09-11 | Name : The remote database server is susceptible to a denial of service attack. File : mysql_es_5_0_66.nasl - Type : ACT_GATHER_INFO |
2008-09-11 | Name : The remote database server is susceptible to a denial of service attack. File : mysql_6_0_6.nasl - Type : ACT_GATHER_INFO |
2008-09-11 | Name : The remote database server is affected by several issues. File : mysql_5_0_67.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-02-17 11:28:26 |
|