-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Wed, 3 Nov 2004 00:09:41 +0100 Source: mysql-dfsg Binary: libmysqlclient12 mysql-client mysql-server mysql-common libmysqlclient-dev Architecture: source i386 all Version: 4.0.22-2 Distribution: unstable Urgency: medium Maintainer: Christian Hammers <ch@debian.org> Changed-By: Christian Hammers <ch@debian.org> Description: libmysqlclient-dev - mysql database development files libmysqlclient12 - mysql database client library mysql-client - mysql database client binaries mysql-common - mysql database common files (e.g. /etc/mysql/my.cnf) mysql-server - mysql database server binaries Changes: mysql-dfsg (4.0.22-2) unstable; urgency=medium . * Many client programs accept plaintext password as command line options. This is insecure as these passwords are visible in /proc/<pid>/cmdline to everybody. As user scripts may rely on these feature, MySQL does not like to remove it. To increase security at least a bit I added warnings to all manpages and --help outputs that seemed relevant to me. (thanks to Jan Minar). See: #278955 Files: 8a22cd80b366777efb7e69ab8fc8fec5 890 misc optional mysql-dfsg_4.0.22-2.dsc 3cc1f6d4743b57789ae8ab5d9ad77b01 96086 misc optional mysql-dfsg_4.0.22-2.diff.gz 6f7dad71eba3c80da4563729b3a1f2c7 29716 misc optional mysql-common_4.0.22-2_all.deb 9e26523f6fc652df1ac41a2e1a70403e 300808 libs optional libmysqlclient12_4.0.22-2_i386.deb f3b9260aabb4c579ff4dbe72dc3fac7b 2925108 libdevel optional libmysqlclient-dev_4.0.22-2_i386.deb ba85f6a556ed7c5c50b32ff19ca27efa 412688 misc optional mysql-client_4.0.22-2_i386.deb 634478c438db734ffba1278807e7de11 3645744 misc optional mysql-server_4.0.22-2_i386.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.5 (GNU/Linux) iEYEARECAAYFAkGILO8ACgkQkR9K5oahGObAtQCdEsi/stUFNV4t90B9y9KYDCdo D64AoLmpMrtzTMJELth3UEILrXM0Gvli =wWrs -----END PGP SIGNATURE----- Accepted: libmysqlclient-dev_4.0.22-2_i386.deb to pool/main/m/mysql-dfsg/libmysqlclient-dev_4.0.22-2_i386.deb libmysqlclient12_4.0.22-2_i386.deb to pool/main/m/mysql-dfsg/libmysqlclient12_4.0.22-2_i386.deb mysql-client_4.0.22-2_i386.deb to pool/main/m/mysql-dfsg/mysql-client_4.0.22-2_i386.deb mysql-common_4.0.22-2_all.deb to pool/main/m/mysql-dfsg/mysql-common_4.0.22-2_all.deb mysql-dfsg_4.0.22-2.diff.gz to pool/main/m/mysql-dfsg/mysql-dfsg_4.0.22-2.diff.gz mysql-dfsg_4.0.22-2.dsc to pool/main/m/mysql-dfsg/mysql-dfsg_4.0.22-2.dsc mysql-server_4.0.22-2_i386.deb to pool/main/m/mysql-dfsg/mysql-server_4.0.22-2_i386.deb -- To UNSUBSCRIBE, email to debian-devel-changes-REQUEST@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org