Bug#675872: mysql-server-5.1: CVE-2012-0882

2013-04-07 Thread Michael Gilbert
clone 675872 -1 reassign -1 src:mysql-5.5 There still isn't much to go on about this issue, but all sign point to it still existing. Note that redhat's mysql packages use openssl instead of yassl; altogether avoiding the uncertainties with yassl, which seems not very supported security-wise. It

Bug#675872: [debian-mysql] Bug#675872: mysql-server-5.1: CVE-2012-0882

2013-04-07 Thread Clint Byrum
On 2013-04-07 19:26, Michael Gilbert wrote: clone 675872 -1 reassign -1 src:mysql-5.5 There still isn't much to go on about this issue, but all sign point to it still existing. Note that redhat's mysql packages use openssl instead of yassl; altogether avoiding the uncertainties with yassl,

Bug#675872: mysql-server-5.1: CVE-2012-0882 - one more underspecified security problem

2012-06-03 Thread Arne Wichmann
Package: mysql-server-5.1 Version: 5.1.61-0+squeeze1 Severity: important Hi. Quoting from the RedHat Bugreport [1]: CVE-2012-0882: unspecified remote exploit (released with VulnDisco Pack Professional 9.17). This is mostly a heads-up as there is not enough information to fix this bug. See

Bug#675872: [debian-mysql] Bug#675872: mysql-server-5.1: CVE-2012-0882 - one more underspecified security problem

2012-06-03 Thread Nicholas Bamber
Arne, The issue sounds a bit like #674267 though I had not perceived the latter to be a security issue. The commonality is as follows: 1.) i386 systems only (well the video does not say its i386 only, but they don't mention anything else). 2.) 5.5.* - the video actually talks about 5.5.20.