pkgsrc/databases/mysql5-server/distinfo
taca 9efce66df2 Update mysql5-{client,server} package to 5.0.91.
For full changes, refer http://dev.mysql.com/doc/refman/5.0/en/news-5-0-91.html.

Here is security related changes.

* Security Fix: The server failed to check the table name argument of
  a COM_FIELD_LIST command packet for validity and compliance to
  acceptable table name standards. This could be exploited to bypass
  almost all forms of checks for privileges and table-level grants by
  providing a specially crafted table name argument to COM_FIELD_LIST.

  In MySQL 5.0 and above, this allowed an authenticated user with
  SELECT privileges on one table to obtain the field definitions of
  any table in all other databases and potentially of other MySQL
  instances accessible from the server's file system.

  Additionally, for MySQL version 5.1 and above, an authenticated user
  with DELETE or SELECT privileges on one table could delete or read
  content from any other table in all databases on this server, and
  potentially of other MySQL instances accessible from the server's
  file system. (Bug#53371, CVE-2010-1848)

* Security Fix: The server was susceptible to a buffer-overflow attack
  due to a failure to perform bounds checking on the table name
  argument of a COM_FIELD_LIST command packet. By sending long data
  for the table name, a buffer is overflown, which could be exploited
  by an authenticated user to inject malicious code. (Bug#53237,
  CVE-2010-1850)

* Security Fix: The server could be tricked into reading packets
  indefinitely if it received a packet larger than the maximum size of
  one packet. (Bug#50974, CVE-2010-1849)
2010-06-02 13:34:45 +00:00

23 lines
1.3 KiB
Text

$NetBSD: distinfo,v 1.25 2010/06/02 13:34:45 taca Exp $
SHA1 (mysql-5.0.91.tar.gz) = 14a79138a1296ce6ebb681fceba622d870feba3e
RMD160 (mysql-5.0.91.tar.gz) = 3aaa638172f6916d3698c5421b24a01647f7e9db
Size (mysql-5.0.91.tar.gz) = 22340514 bytes
SHA1 (patch-aa) = f52745512abfb2c2d43715975f76c2f454ed93e5
SHA1 (patch-ab) = 7c51a0214c3e6205605047c72b07eac6792600db
SHA1 (patch-ae) = dc67ad03f9ea370b17a45f73e974013e0ac48d71
SHA1 (patch-af) = 256de04aefd067ac7bdf8a6d1d817723efa6c6ec
SHA1 (patch-ag) = abc6b85dd7d72b980f0768166eb77618d50e5102
SHA1 (patch-ah) = 822f1f0eace49ff44f03e708056b88e480443c15
SHA1 (patch-ai) = 56d3f66a903224b8d27213480e7ea3e485e52f1d
SHA1 (patch-aj) = b8516c18b1c2be5b3492ece583e9b8a85b89331a
SHA1 (patch-ak) = 27698a132b42519e267dda0584a75eae1b74edea
SHA1 (patch-al) = a8232565e70d199b77e044152dee3df52564724b
SHA1 (patch-am) = cc551d150c5b0adee8906d428b87bdc88ea47a05
SHA1 (patch-an) = 1f7ede981f2e7a846f49a5cfd443051acf9f3a02
SHA1 (patch-ap) = 70049d00e30d89201dd8d9fc0ace4e6edfcffae7
SHA1 (patch-aq) = e63b5be7cb1cb2e8ca8ee52e7e42632c05804959
SHA1 (patch-bf) = 180aefb012a0d17269654ba0aeb71ec74ea98e6c
SHA1 (patch-ca) = 8d3f658a44a8d225a362b7f6135c772ee53ba5e3
SHA1 (patch-cb) = b3a6bcc6f201b3ba1068ebe2d0cef3fbb22ab621
SHA1 (patch-cc) = 2d1347ba57e35da484edd4fa3c764441ec6a80ed