Bug#687485: mysql-5.5: CVE-2012-4414

2012-09-21 Thread Nicholas Bamber
On 21/09/12 12:32, Nicholas Bamber wrote: > On 20/09/12 22:33, Moritz Muehlenhoff wrote: >> On Wed, Sep 19, 2012 at 07:07:23PM +0100, Nicholas Bamber wrote: >>> I am looking at this bug. However the patch involves 45 files. 17 of >>> these are test files. From what I have seen so far they do not ap

Bug#687485: mysql-5.5: CVE-2012-4414

2012-09-20 Thread Moritz Muehlenhoff
On Wed, Sep 19, 2012 at 07:07:23PM +0100, Nicholas Bamber wrote: > I am looking at this bug. However the patch involves 45 files. 17 of > these are test files. From what I have seen so far they do not apply > cleanly. Presumably they are meant for 5.5.27 rather than 5.5.24. I have > yet to form a j

Bug#687485: mysql-5.5: CVE-2012-4414

2012-09-19 Thread Nicholas Bamber
On 19/09/12 19:07, Nicholas Bamber wrote: > I am looking at this bug. However the patch involves 45 files. 17 of > these are test files. From what I have seen so far they do not apply > cleanly. Presumably they are meant for 5.5.27 rather than 5.5.24. I have > yet to form a judgement on quite how i

Bug#687485: mysql-5.5: CVE-2012-4414

2012-09-19 Thread Nicholas Bamber
I am looking at this bug. However the patch involves 45 files. 17 of these are test files. From what I have seen so far they do not apply cleanly. Presumably they are meant for 5.5.27 rather than 5.5.24. I have yet to form a judgement on quite how intractable adapting the patch is going to be. --

Bug#687485: mysql-5.5: CVE-2012-4414

2012-09-13 Thread Moritz Muehlenhoff
Package: mysql-5.5 Severity: grave Tags: security Justification: user security hole Please see https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-4414 for details and patches. Cheers, Moritz -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubs