Family: Mandrake Local Security Checks --> Category: infos
MDKSA-2004:034: MySQL Vulnerability Scan
Vulnerability Scan Summary
Check for the version of the MySQL package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory MDKSA-2004:034 (MySQL).
Shaun Colley discovered that two scripts distributed with MySQL, the
'mysqld_multi' and 'mysqlbug' scripts, did not create temporary files in a
secure fashion. A possible hacker could create symbolic links in /tmp that could allow
for overwriting of files with the rights of the user running the scripts.
The scripts have been patched in the updated packages to prevent this behaviour.
Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2004:034
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.