Get a Pentest and security assessment of your IT network.

Advisories

Mandriva Linux Security Advisory 2008-028

Mandriva Linux Security Advisory – The mysql_change_db() function in MySQL 5.0.x before 5.0.40 did not restore THD::db_access privileges when returning from SQL SECURITY INVOKER stored routines, which allowed remote authenticated users to gain privileges. The federated engine in MySQL 5.0.x, when performing a certain SHOW TABLE STATUS query, did not properly handle a response with a small number of columns, which could allow a remote MySQL server to cause a denial of service (federated handler crash and daemon crash) via a response that lacks the minimum required number of columns.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/63124/MDVSA-2008-028.txt

Source: https://packetstormsecurity.com/files/63124/Mandriva-Linux-Security-Advisory-2008-028.html

Related posts
Advisories

Secunia Security Advisory 15646

Advisories

Secunia Security Advisory 18761

Advisories

deluxeBBflaws.txt

Advisories

Mandriva Linux Security Advisory 2007.061