Debian DSA-2429-1 : mysql-5.1 - several vulnerabilities

medium Nessus Plugin ID 58277

Synopsis

The remote Debian host is missing a security-related update.

Description

Due to the non-disclosure of security patch information from Oracle, we are forced to ship an upstream version update of MySQL 5.1. There are several known incompatible changes, which are listed in /usr/share/doc/mysql-server/NEWS.Debian.gz.

Several security vulnerabilities were discovered in MySQL, a database management system. The vulnerabilities are addressed by upgrading MySQL to a new upstream version, 5.1.61, which includes additional changes, such as performance improvements and corrections for data loss defects. These changes are described in the MySQL release notes at: .

Solution

Upgrade the mysql-5.1 packages.

For the stable distribution (squeeze), these problems have been fixed in version 5.1.61-0+squeeze1.

See Also

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=659687

https://packages.debian.org/source/squeeze/mysql-5.1

https://www.debian.org/security/2012/dsa-2429

Plugin Details

Severity: Medium

ID: 58277

File Name: debian_DSA-2429.nasl

Version: 1.14

Type: local

Agent: unix

Published: 3/8/2012

Updated: 1/11/2021

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.7

CVSS v2

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.1

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:N/A:P

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:mysql-5.1, cpe:/o:debian:debian_linux:6.0

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Ease: No known exploits are available

Patch Publication Date: 3/7/2012

Vulnerability Publication Date: 1/18/2012

Reference Information

CVE: CVE-2011-2262, CVE-2012-0075, CVE-2012-0087, CVE-2012-0101, CVE-2012-0102, CVE-2012-0112, CVE-2012-0113, CVE-2012-0114, CVE-2012-0115, CVE-2012-0116, CVE-2012-0118, CVE-2012-0119, CVE-2012-0120, CVE-2012-0484, CVE-2012-0485, CVE-2012-0490, CVE-2012-0492

BID: 51488, 51493, 51502, 51504, 51505, 51508, 51509, 51511, 51512, 51513, 51515, 51516, 51517, 51519, 51520, 51524, 51526

DSA: 2429