Vulnerability Scanning Solutions, LLC.
Home
Our Process
Residential
Corporate
What We Scan For
Sample Report
Client List
Terms
Contact Us
What We Scan For
Family: Ubuntu Local Security Checks --> Category: infos

USN274-1 : mysql-dfsg vulnerability Vulnerability Scan


Vulnerability Scan Summary
mysql-dfsg vulnerability

Detailed Explanation for this Vulnerability Test

Synopsis :

These remote packages are missing security patches :
- libmysqlclient-dev
- libmysqlclient12
- libmysqlclient12-dev
- mysql-client
- mysql-common
- mysql-server


Description :

A logging bypass was discovered in the MySQL query parser. A local
attacker could exploit this by inserting NUL characters into query
strings (even into comments), which would cause the query to be logged
incompletely.

This only affects you if you enabled the 'log' parameter in the MySQL
configuration.

Solution :

Upgrade to :
- libmysqlclient-dev-4.0.20-2ubuntu1.7 (Ubuntu 4.10)
- libmysqlclient12-4.0.24-10ubuntu2.1 (Ubuntu 5.10)
- libmysqlclient12-dev-4.0.24-10ubuntu2.1 (Ubuntu 5.10)
- mysql-client-4.0.24-10ubuntu2.1 (Ubuntu 5.10)
- mysql-common-4.0.24-10ubuntu2.1 (Ubuntu 5.10)
- mysql-server-4.0.24-10ubuntu2.1 (Ubuntu 5.10)



Threat Level: High


Click HERE for more information and discussions on this network vulnerability scan.

VSS, LLC.

P.O. Box 827051

Pembroke Pines, FL 33082-7051

Vulnerability Scanning Solutions, LLC.