-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Thu, 13 Jan 2005 02:50:21 +0100 Source: mysql Binary: mysql-common libmysqlclient10 mysql-server mysql-client libmysqlclient10-dev Architecture: source mipsel all Version: 3.23.49-8.9 Distribution: stable-security Urgency: high Maintainer: Christian Hammers <ch@debian.org> Changed-By: Christian Hammers <ch@debian.org> Description: libmysqlclient10 - mysql database client library libmysqlclient10-dev - mysql database development files mysql-client - mysql database client binaries mysql-common - mysql database common files (e.g. /etc/mysql/my.cnf) mysql-server - mysql database server binaries Changes: mysql (3.23.49-8.9) stable-security; urgency=high . * Maintainer upload for the Security Team * Javier Fernandez-Sanguino Pena from the Debian Security Audit Project found a /tmp symlink vulnerability in the mysqlaccess script that could allow an unprivileged user to let root overwrite arbitrary files without his knowledge and also could unveil the contents of a temporary file which might contain sensitive information. [scripts/mysqlaccess.sh, CAN-2005-0004] * Added older security patches to debian/patches for reference Files: 943c6c647b130518c2a6c96bcb9c4031 875 misc optional mysql_3.23.49-8.9.dsc 7c46ef730e9c81c554b6d511481c02b7 68320 misc optional mysql_3.23.49-8.9.diff.gz 9c6cf59a839d3fc25a74f164358008e2 17484 misc optional mysql-common_3.23.49-8.9_all.deb 73d7c69f49a13e8e3592310c2bc675e0 251192 libs optional libmysqlclient10_3.23.49-8.9_mipsel.deb f13325c3394b0385c76d289d886f165f 689122 devel optional libmysqlclient10-dev_3.23.49-8.9_mipsel.deb 6d0e79f252d1cd3048ce3367aa200636 134828 misc optional mysql-client_3.23.49-8.9_mipsel.deb 499551d692fc5d80fd16c43e83e19201 2839732 misc optional mysql-server_3.23.49-8.9_mipsel.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.5 (GNU/Linux) iD8DBQFB5obwW5ql+IAeqTIRAiyXAKCQC8aHPDzfJK9hlhWbXxQ3nHr32QCdGvDF t7hEp2z0+QL3AnU0va/g3y4= =hRnR -----END PGP SIGNATURE----- Accepted: libmysqlclient10-dev_3.23.49-8.9_mipsel.deb to pool/main/m/mysql/libmysqlclient10-dev_3.23.49-8.9_mipsel.deb libmysqlclient10_3.23.49-8.9_mipsel.deb to pool/main/m/mysql/libmysqlclient10_3.23.49-8.9_mipsel.deb mysql-client_3.23.49-8.9_mipsel.deb to pool/main/m/mysql/mysql-client_3.23.49-8.9_mipsel.deb mysql-common_3.23.49-8.9_all.deb to pool/main/m/mysql/mysql-common_3.23.49-8.9_all.deb mysql-server_3.23.49-8.9_mipsel.deb to pool/main/m/mysql/mysql-server_3.23.49-8.9_mipsel.deb mysql_3.23.49-8.9.diff.gz to pool/main/m/mysql/mysql_3.23.49-8.9.diff.gz mysql_3.23.49-8.9.dsc to pool/main/m/mysql/mysql_3.23.49-8.9.dsc