Re: MySQL command-line client HTML injection vulnerability

2008-10-29 Thread okuno
Hi, Thank you for your correction of version numbers from 5.0.26 through 5.0.45 to any. However, it appears that CVE report still shows the wrong version numbers. Could you please kindly correct CVE report too? Kind regards, -- Mikiya Okuno, MySQL Support Engineer Sun Microsystems KK, To

Re: MySQL command-line client HTML injection vulnerability

2008-10-08 Thread Michael Scheidell
> Hi Thomas, > > This bug was fixed in a MySQL release dated 01 May 2008. It is now 01 > Oct 2008 - 5 months after the bug was released. So why exactly is this > news? Did I miss something here? Not fixed in any version I know of. Patch has been available for 5 months, but this has not gotten

RE: RE: MySQL command-line client HTML injection vulnerability

2008-10-06 Thread Quark IT - Hilton Travis
Hi, So, should we bring up all patches that have been released 5 months ago or thereabouts? There's been a LOT of serious vulnerabilities released since then - if you're 5 months behind in patching, then there's more serious questions than this one patch. We ALL need to keep up to date with patc

Re: RE: MySQL command-line client HTML injection vulnerability

2008-10-03 Thread mrry . dmlo
what about the people who do not know about the bug or the patch? Mr. Travis Hilton so it shouldnt be brought to my attention? it is a very serious bug does one ever go to the root of any problems?

RE: MySQL command-line client HTML injection vulnerability

2008-10-01 Thread Quark IT - Hilton Travis
Hi Thomas, This bug was fixed in a MySQL release dated 01 May 2008. It is now 01 Oct 2008 - 5 months after the bug was released. So why exactly is this news? Did I miss something here? -- http://blog.hiltontravis.com/ Regards, Hilton Travis Phone: +61 (0)7 3105 9101 (B