Bug#455737: [debian-mysql] Bug#455737: more CVEs

2007-12-12 Thread Norbert Tretkowski
Am Dienstag, den 11.12.2007, 20:08 +0100 schrieb Steffen Joeris: CVE-2007-5968: This CVE was rejected, see http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5968 Norbert -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL

Bug#455737: [debian-mysql] Bug#455737: Bug#455737: more CVEs

2007-12-12 Thread Norbert Tretkowski
Am Mittwoch, den 12.12.2007, 10:08 +0100 schrieb Norbert Tretkowski: Am Dienstag, den 11.12.2007, 20:08 +0100 schrieb Steffen Joeris: CVE-2007-5968: This CVE was rejected, see http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5968 It's still an issue, but doesn't affect 5.0.x.

Bug#455737: [debian-mysql] Bug#455737: Bug#455737: more CVEs

2007-12-12 Thread Nico Golde
Hi, * Norbert Tretkowski [EMAIL PROTECTED] [2007-12-12 13:49]: Am Mittwoch, den 12.12.2007, 10:08 +0100 schrieb Norbert Tretkowski: Am Dienstag, den 11.12.2007, 20:08 +0100 schrieb Steffen Joeris: CVE-2007-5968: This CVE was rejected, see

Bug#455737: more CVEs

2007-12-11 Thread Steffen Joeris
Hi There are two more CVEs[0][1] against mysql-dfsg-5.0. CVE-2007-5968: MySQL 5.1.x before 5.1.23 might allow attackers to gain privileges via unspecified use of the BINLOG statement in conjunction with the binlog filename, which is interpreted as an absolute path by some components of the

Bug#455737: more CVEs

2007-12-11 Thread Steffen Joeris
Hi Patch: http://lists.mysql.com/commits/37098 Patch: http://bugs.mysql.com/bug.php?id=29908 Please rather check the full bugreports, instead of the individual commit messages, because there was more. For references: http://bugs.mysql.com/bug.php?id=28597