SuSE 10 Security Update : MySQL (ZYPP Patch Number 5338)
Medium Nessus Plugin ID 33886
SynopsisThe remote SuSE 10 host is missing a security-related patch.
DescriptionThe database server mySQL was updated to fix two security problems :
- MySQL allowed local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are within the MySQL home data directory, which can point to tables that are created in the future. (CVE-2008-2079)
- sql_select.cc in MySQL 5.0.x before 5.0.32 and 5.1.x before 5.1.14 allows remote authenticated users to cause a denial of service (crash) via an EXPLAIN SELECT FROM on the INFORMATION_SCHEMA table, as originally demonstrated using ORDER BY. (CVE-2006-7232)
SolutionApply ZYPP patch number 5338.