|
|
To print: Select File and then Print from your browser's menu
-------------------------------------------------------------- This story was printed from ZDNet Australia. --------------------------------------------------------------
|
MySQL issues security fix By Dawn Kawamoto, CNET News.com May 05, 2006 URL: http://www.zdnet.com.au/news/security/soa/MySQL-issues-security-fix/0,130061744,139255427,00.htm
MySQL has issued a security update to address flaws in its client-server protocol that could allow a malicious attacker to exploit buffer overflow vulnerabilities and gain access to sensitive information. The open-source database company released its MySQL version 5.0.21 update earlier this week. The update is designed to address security flaws in database server software versions 5.1.9; 5.0.20; 4.1.18; 4.0.26 and prior versions. Security researcher FrSIRT rates the flaws as "moderate" risk. MySQL's version 5.0, which was announced late last year, is considered to be in widespread use. FrSIRT noted that one of the three flaws involves a buffer overflow flaw, which could be exploited by attackers to execute arbitrary commands from a user's system. The two other flaws can be exploited when a validation error occurs when inputting information. The vulnerabilities could allow attackers to disclose portions of the system's memory in the error messages.
Copyright © 2009 CBS Interactive, a CBS Company. All Rights Reserved. |