-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Christopher E. Brown wrote:
Description:
	MySQL 4.0.8, both compiled my me and the official release version
crashes whenever receiving a network connection from a system without a DNS
entry.  Connecting from a system that resolves on reverse (eithor from DNS
or a local hosts file entry) works find.  This system is a Slackware 8.1
install with all currect updates.  I do not know if this is a mysqld
internal thing or some interaction with the system resolver in glibc 2.2.5,
as unfort even a staticly compiled glibc binary uses the system resolver.

	This of course concerns me, there is a large potential for remote
DoS here.


How-To-Repeat:
	Install 4.0.8, run the install db script and fire it up.  Attempt to
connect from a host that will not reverse resolve.  Even a telnet to port
3306 crashed the daemon.  The dump from mysqld is included at the bottom of
the message.
This was fixed in the source tree last night, and will be in the 4.0.9 release, which is being built as this is being written, and released ASAP.

-Mark

- -- MySQL 2003 Users Conference -> http://www.mysql.com/events/uc2003/

For technical support contracts, visit https://order.mysql.com/?ref=mmma

__ ___ ___ ____ __
/ |/ /_ __/ __/ __ \/ / Mark Matthews <[EMAIL PROTECTED]>
/ /|_/ / // /\ \/ /_/ / /__ MySQL AB, Full-Time Developer - JDBC/Java
/_/ /_/\_, /___/\___\_\___/ Flossmoor (Chicago), IL USA
<___/ www.mysql.com
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.1.90 (MingW32)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQE+HcfitvXNTca6JD8RAt0RAKCxwM9hsmBRjmk3rQLXciv20QU1MACfUiZQ
AYzgNkfelbpRMjth7dXKwgM=
=xGQF
-----END PGP SIGNATURE-----


---------------------------------------------------------------------
Before posting, please check:
http://www.mysql.com/manual.php (the manual)
http://lists.mysql.com/ (the list archive)

To request this thread, e-mail <[EMAIL PROTECTED]>
To unsubscribe, e-mail <[EMAIL PROTECTED]>
Trouble unsubscribing? Try: http://lists.mysql.com/php/unsubscribe.php

Reply via email to