Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Mysql vulnerability fixed?

Status
Not open for further replies.

mhamilton3

Programmer
Oct 31, 2001
129
I have had the following vulnerability reported to me (using a program called FoundScan) and I am trying to find out if this bug was patched, but I can not find any documentation on it. Any suggestions on where I should look. I went to mysql.org and did not have any luck finding if they recongized the problem or if it was fixed.

MySQL allows authorized users to switch to a different user account using the COM_CHANGE_USER command. Inadequate bounds checking allows any password greater than 16 characters that is parsed by COM_CHANGE_USER to cause a buffer overflow condition. Arbitrary data outside the buffer may be executed with elevated privileged or cause the MySQL daemon (mysqld) to crash. This allows attackers with access to a valid account to cause a denial-of-service condition or run arbitrary code on the targeted host.


Vulnerable systems:

MySQL 3.23.53 and earlier
MySQL 4.0 - 4.0.5 a

Any help would be great, thanks
 
It does not fall under the vulnerable systems, but I can not find out when the problem was patched. I need confirmation that this whole is closed and I don't know where to go to find it. Any thoughts? I am at 4.0.17
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top