severity 418672 normal
tags 418672 - security
tags 418672 + unreproducible moreinfo
stop

Hi Olaf

On 2007-04-11 Olaf van der Spek wrote:
> I pressed Enter when it asked for a new password for root (root already
> had a password). Three rows were inserted into mysql.user:

> (0x6c6f63616c686f7374, 0x726f6f74, '', 'Y', 'Y', 'Y', 'Y', 'Y', 'Y', 'Y',
> 'Y', 'Y', 'Y', 'Y', 'Y', 'Y', 'Y', 'Y', 'Y', 'Y', 'Y', 'Y', 'Y', 'Y', 'Y',
> 'Y', 'Y', 'Y', 'Y', '', '', '', '', 0, 0, 0, 0), (0x632e787769732e6e6574,
> 0x726f6f74, '', 'Y', 'Y', 'Y', 'Y', 'Y', 'Y', 'Y', 'Y', 'Y', 'Y', 'Y',
> 'Y', 'Y', 'Y', 'Y', 'Y', 'Y', 'Y', 'Y', 'Y', 'Y', 'Y', 'Y', 'Y', 'Y', 'Y',
> '', '', '', '', 0, 0, 0, 0), (0x3132372e302e302e31, 0x726f6f74, '', 'Y',
> 'Y', 'Y', 'Y', 'Y', 'Y', 'Y', 'Y', 'Y', 'Y', 'Y', 'Y', 'Y', 'Y', 'Y', 'Y',
> 'Y', 'Y', 'Y', 'Y', 'Y', 'Y', 'Y', 'Y', 'Y', 'Y', '', '', '', '', 0, 0, 0,
> 0);

Those hex numbers translate to 'localhost', 'root' and '127.0.0.1' and there
are no quotes around them so I guess you set some special options to have
them displayed in such a strange way?

Anyway, I cannot reproduce a reset of the users passwords during a mysql
upgrade or "dpkg --reconfigure mysql-server-5.0". Can you try to reproduce
it yourself?

Also, please check against your backups and /var/log/mysql/ that you
*really* had a password set.

Are there other rows in the user table? Maybe some with a set password
and some without?

bye,

-christian-

Attachment: signature.asc
Description: PGP signature

Reply via email to