漏洞信息详情
Oracle MySQL SQL_parse.cc 格式化字符串错误漏洞
漏洞简介
Oracle MySQL是美国甲骨文(Oracle)公司的一套开源的关系数据库管理系统。
Oracle MySQL的sql_parse.cc文件中的dispatch_command()函数存在格式化字符串错误漏洞。攻击者可通过提交特制的COM_CREATE_DB或COM_DROP_DB请求利用该漏洞导致受影响的服务崩溃。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
Debian Linux 5.0 alpha
Debian libmysqlclient15-dev_5.0.51a-24+lenny2_alpha.deb
http://security.debian.org/pool/updates/main/m/mysql-dfsg-5.0/libmysql client15-dev_5.0.51a-24+lenny2_alpha.deb
Debian libmysqlclient15off_5.0.51a-24+lenny2_alpha.deb
http://security.debian.org/pool/updates/main/m/mysql-dfsg-5.0/libmysql client15off_5.0.51a-24+lenny2_alpha.deb
Debian mysql-client-5.0_5.0.51a-24+lenny2_alpha.deb
http://security.debian.org/pool/updates/main/m/mysql-dfsg-5.0/mysql-cl ient-5.0_5.0.51a-24+lenny2_alpha.deb
Debian mysql-client_5.0.51a-24+lenny2_all.deb
http://security.debian.org/pool/updates/main/m/mysql-dfsg-5.0/mysql-cl ient_5.0.51a-24+lenny2_all.deb
Debian mysql-common_5.0.51a-24+lenny2_all.deb
http://security.debian.org/pool/updates/main/m/mysql-dfsg-5.0/mysql-co mmon_5.0.51a-24+lenny2_all.deb
Debian mysql-server-5.0_5.0.51a-24+lenny2_alpha.deb
http://security.debian.org/pool/updates/main/m/mysql-dfsg-5.0/mysql-se rver-5.0_5.0.51a-24+lenny2_alpha.deb
Debian mysql-server_5.0.51a-24+lenny2_all.deb
http://security.debian.org/pool/updates/main/m/mysql-dfsg-5.0/mysql-se rver_5.0.51a-24+lenny2_all.deb
MandrakeSoft Linux Mandrake 2008.0
Mandriva libmysql-devel-5.0.45-8.3mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/
Mandriva libmysql-static-devel-5.0.45-8.3mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/
Mandriva libmysql15-5.0.45-8.3mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/
Mandriva mysql-5.0.45-8.3mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/
Mandriva mysql-bench-5.0.45-8.3mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/
Mandriva mysql-client-5.0.45-8.3mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/
Mandriva mysql-common-5.0.45-8.3mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/
Mandriva mysql-max-5.0.45-8.3mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/
Mandriva mysql-ndb-extra-5.0.45-8.3mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/
Mandriva mysql-ndb-management-5.0.45-8.3mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/
Mandriva mysql-ndb-storage-5.0.45-8.3mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/
Mandriva mysql-ndb-tools-5.0.45-8.3mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/
Debian Linux 4.0 amd64
Debian libmysqlclient15-dev_5.0.32-7etch11_amd64.deb
http://security.debian.org/pool/updates/main/m/mysql-dfsg-5.0/libmysql client15-dev_5.0.32-7etch11_amd64.deb
Debian libmysqlclient15off_5.0.32-7etch11_amd64.deb
http://security.debian.org/pool/updates/main/m/mysql-dfsg-5.0/libmysql client15off_5.0.32-7etch11_amd64.deb
Debian mysql-client-5.0_5.0.32-7etch11_amd64.deb
http://security.debian.org/pool/updates/main/m/mysql-dfsg-5.0/mysql-cl ient-5.0_5.0.32-7etch11_amd64.deb
Debian mysql-client_5.0.32-7etch11_all.deb
http://security.debian.org/pool/updates/main/m/mysql-dfsg-5.0/mysql-cl ient_5.0.32-7etch11_all.deb
Debian mysql-common_5.0.32-7etch11_all.deb
http://security.debian.org/pool/updates/main/m/mysql-dfsg-5.0/mysql-co mmon_5.0.32-7etch11_all.deb
Debian mysql-server-4.1_5.0.32-7etch11_amd64.deb
http://security.debian.org/pool/updates/main/m/mysql-dfsg-5.0/mysql-se rver-4.1_5.0.32-7etch11_amd64.deb
Debian mysql-server-5.0_5.0.32-7etch11_amd64.deb
http://security.debian.org/pool/updates/main/m/mysql-dfsg-5.0/mysql-se rver-5.0_5.0.32-7etch11_amd64.deb
Debian mysql-server_5.0.32-7etch11_all.deb
http://security.debian.org/pool/updates/main/m/mysql-dfsg-5.0/mysql-se rver_5.0.32-7etch11_all.deb
Debian Linux 4.0 ia-32
Debian libmysqlclient15-dev_5.0.32-7etch11_i386.deb
http://security.debian.org/pool/updates/main/m/mysql-dfsg-5.0/libmysql client15-dev_5.0.32-7etch11_i386.deb
Debian libmysqlclient15off_5.0.32-7etch11_i386.deb
http://security.debian.org/pool/updates/main/m/mysql-dfsg-5.0/libmysql client15off_5.0.32-7etch11_i386.deb
Debian mysql-client-5.0_5.0.32-7etch11_i386.deb
http://security.debian.org/pool/updates/main/m/mysql-dfsg-5.0/mysql-cl ient-5.0_5.0.32-7etch11_i386.deb
Debian mysql-client_5.0.32-7etch11_all.
参考网址
来源:UBUNTU
链接:http://ubuntu.com/usn/usn-897-1
来源:APPLE
链接:http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html
来源:REDHAT
链接:http://www.redhat.com/support/errata/RHSA-2009-1289.html
来源:SECTRACK
链接:http://securitytracker.com/id?1022533
来源:BUGTRAQ
链接:http://www.securityfocus.com/archive/1/504799/100/0/threaded
来源:REDHAT
链接:http://www.redhat.com/support/errata/RHSA-2010-0110.html
来源:MANDRIVA
链接:http://www.mandriva.com/security/advisories?name=MDVSA-2009:179
来源:BID
链接:https://www.securityfocus.com/bid/35609
来源:XF
链接:https://exchange.xforce.ibmcloud.com/vulnerabilities/51614
来源:FULLDISC
链接:http://archives.neohapsis.com/archives/fulldisclosure/2009-07/0058.html
来源:SECUNIA
链接:http://secunia.com/advisories/38517
来源:OVAL
链接:https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11857
来源:SECUNIA
链接:http://secunia.com/advisories/36566
来源:SECUNIA
链接:http://secunia.com/advisories/35767
来源:VUPEN
链接:http://www.vupen.com/english/advisories/2009/1857
来源:OSVDB
链接:http://www.osvdb.org/55734
来源:CONFIRM
链接:http://support.apple.com/kb/HT4077
来源:UBUNTU
链接:http://www.ubuntu.com/usn/USN-1397-1
受影响实体
- Mysql Mysql:4.0.9<!--2000-1-1-->
- Mysql Mysql:4.0.8:Gamma<!--2000-1-1-->
- Mysql Mysql:4.0.5<!--2000-1-1-->
- Mysql Mysql:4.0.8<!--2000-1-1-->
- Mysql Mysql:4.0.7<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...