Bug#373913: Bug#375694: Status of last two, not yet DSA'd, MySQL security bugs

2006-07-10 Thread Christian Hammers
On 2006-07-10 Steven M. Christey wrote: > Speaking of MySQL, the following item recently showed up in an FrSIRT > advisory. In light of last week's vendor-sec discussions, let me know if > there's too much guesswork going on here :) I asked FrSIRT and MySQL if they have more information, and re

Bug#375694: Status of last two, not yet DSA'd, MySQL security bugs

2006-07-10 Thread Steven M. Christey
Speaking of MySQL, the following item recently showed up in an FrSIRT advisory. In light of last week's vendor-sec discussions, let me know if there's too much guesswork going on here :) - Steve == Name: CVE-2006-3486 Status: Candidate URL: ht

Bug#375694: Status of last two, not yet DSA'd, MySQL security bugs

2006-07-10 Thread Steven M. Christey
On Sun, 9 Jul 2006, Moritz Muehlenhoff wrote: > > On 2006-07-04 Christian Hammers wrote: > > > It's time for a new MySQL DSA :) On > > > http://www.lathspell.de/linux/debian/mysql/sarge-4.1 > > > you find *sarge5.deb pacakges that fix the following two vulnerabilities: > > > > > >* Fixed Do

Bug#375694: Status of last two, not yet DSA'd, MySQL security bugs

2006-07-09 Thread Christian Hammers
Hello On 2006-07-04 Christian Hammers wrote: > It's time for a new MySQL DSA :) On > http://www.lathspell.de/linux/debian/mysql/sarge-4.1 > you find *sarge5.deb pacakges that fix the following two vulnerabilities: > >* Fixed DoS bug where any user could crash the server with > "SELECT