Debian Bug report logs - #426353
CVE-2007-2583: DoS in item_cmpfunc.cc (MySQL#27513)

version graph

Package: mysql-server-5.0; Maintainer for mysql-server-5.0 is (unknown);

Reported by: Okulov Vitaliy <vitaliy.okulov@gmail.com>

Date: Mon, 28 May 2007 06:21:02 UTC

Severity: critical

Tags: security

Found in version mysql-dfsg-5.0/5.0.30-3

Fixed in versions 5.0.40, 5.0.32-7etch2, 5.0.41-1

Done: Norbert Tretkowski <norbert@tretkowski.de>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, Debian MySQL Maintainers <pkg-mysql-maint@lists.alioth.debian.org>:
Bug#426353; Package mysql-server-5.0. Full text and rfc822 format available.

Acknowledgement sent to Okulov Vitaliy <vitaliy.okulov@gmail.com>:
New Bug report received and forwarded. Copy sent to Debian MySQL Maintainers <pkg-mysql-maint@lists.alioth.debian.org>. Full text and rfc822 format available.

Message #5 received at submit@bugs.debian.org (full text, mbox):

From: Okulov Vitaliy <vitaliy.okulov@gmail.com>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: mysql-server-5.0: Please add patch for this bug to stable mysql-5.0 server. http://bugs.mysql.com/bug.php?id=27513
Date: Mon, 28 May 2007 10:20:18 +0400
Package: mysql-server-5.0
Version: 5.0.30-3
Severity: critical
Justification: breaks unrelated software

Please add patch for this bug to stable mysql-5.0 server.
http://bugs.mysql.com/bug.php?id=27513



-- System Information:
Debian Release: 4.0
  APT prefers stable
  APT policy: (500, 'stable')
Architecture: i386 (i686)
Shell:  /bin/sh linked to /bin/bash
Kernel: Linux 2.6.18-3-xen-686
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)

Versions of packages mysql-server-5.0 depends on:
ii  adduser                     3.100        Add and remove users and groups
ii  debconf [debconf-2.0]       1.5.11       Debian configuration management sy
ii  libc6                       2.3.6.ds1-8  GNU C Library: Shared libraries
ii  libdbi-perl                 1.53-1       Perl5 database interface by Tim Bu
ii  libgcc1                     1:4.1.1-19   GCC support library
ii  libmysqlclient15off         5.0.30-3     mysql database client library
ii  libncurses5                 5.5-5        Shared libraries for terminal hand
ii  libreadline5                5.2-1        GNU readline and history libraries
ii  libstdc++6                  4.1.1-19     The GNU Standard C++ Library v3
ii  libwrap0                    7.6.dbs-11   Wietse Venema's TCP wrappers libra
ii  lsb-base                    3.1-22       Linux Standard Base 3.1 init scrip
ii  mysql-client-5.0            5.0.30-3     mysql database client binaries
ii  mysql-common                5.0.30-3     mysql database common files (e.g. 
ii  passwd                      1:4.0.18.1-6 change and administer password and
ii  perl                        5.8.8-7      Larry Wall's Practical Extraction 
ii  psmisc                      22.3-1       Utilities that use the proc filesy
ii  zlib1g                      1:1.2.3-13   compression library - runtime

Versions of packages mysql-server-5.0 recommends:
ii  mailx            1:8.1.2-0.20050715cvs-1 A simple mail user agent

-- debconf information:
  mysql-server/root_password: (password omitted)
  mysql-server-5.0/really_downgrade: false
  mysql-server-5.0/need_sarge_compat: false
  mysql-server-5.0/start_on_boot: true
  mysql-server/error_setting_password:
  mysql-server-5.0/nis_warning:
  mysql-server-5.0/postrm_remove_databases: false
  mysql-server-5.0/need_sarge_compat_done: true



Information forwarded to debian-bugs-dist@lists.debian.org, Debian MySQL Maintainers <pkg-mysql-maint@lists.alioth.debian.org>:
Bug#426353; Package mysql-server-5.0. Full text and rfc822 format available.

Acknowledgement sent to sean finney <seanius@debian.org>:
Extra info received and forwarded to list. Copy sent to Debian MySQL Maintainers <pkg-mysql-maint@lists.alioth.debian.org>. Full text and rfc822 format available.

Message #10 received at 426353@bugs.debian.org (full text, mbox):

From: sean finney <seanius@debian.org>
To: Okulov Vitaliy <vitaliy.okulov@gmail.com>, 426353@bugs.debian.org
Subject: Re: Bug#426353: mysql-server-5.0: Please add patch for this bug to stable mysql-5.0 server. http://bugs.mysql.com/bug.php?id=27513
Date: Mon, 28 May 2007 08:32:03 +0200
[Message part 1 (text/plain, inline)]
hi vitaliy,

On Monday 28 May 2007 08:20:18 Okulov Vitaliy wrote:
> Package: mysql-server-5.0
> Version: 5.0.30-3
> Severity: critical
> Justification: breaks unrelated software
>
> Please add patch for this bug to stable mysql-5.0 server.
> http://bugs.mysql.com/bug.php?id=27513

yes, someone has shown this one to me and i already have a patch in 
subversion.  i'll close this bug when we make the security update.


	sean
[signature.asc (application/pgp-signature, inline)]

Information forwarded to debian-bugs-dist@lists.debian.org, Debian MySQL Maintainers <pkg-mysql-maint@lists.alioth.debian.org>:
Bug#426353; Package mysql-server-5.0. Full text and rfc822 format available.

Acknowledgement sent to Vitaliy Okulov <vitaliy.okulov@gmail.com>:
Extra info received and forwarded to list. Copy sent to Debian MySQL Maintainers <pkg-mysql-maint@lists.alioth.debian.org>. Full text and rfc822 format available.

Message #15 received at 426353@bugs.debian.org (full text, mbox):

From: Vitaliy Okulov <vitaliy.okulov@gmail.com>
To: sean finney <seanius@debian.org>
Cc: 426353@bugs.debian.org
Subject: Re[2]: Bug#426353: mysql-server-5.0: Please add patch for this bug to stable mysql-5.0 server. http://bugs.mysql.com/bug.php?id=27513
Date: Mon, 28 May 2007 10:43:17 +0400
Здравствуйте, sean.

Вы писали 28 мая 2007 г., 10:32:03:

> hi vitaliy,

> On Monday 28 May 2007 08:20:18 Okulov Vitaliy wrote:
>> Package: mysql-server-5.0
>> Version: 5.0.30-3
>> Severity: critical
>> Justification: breaks unrelated software
>>
>> Please add patch for this bug to stable mysql-5.0 server.
>> http://bugs.mysql.com/bug.php?id=27513

> yes, someone has shown this one to me and i already have a patch in 
> subversion.  i'll close this bug when we make the security update.


>         sean

Ok. Good news.

-- 
С уважением,
 Vitaliy                          mailto:vitaliy.okulov@gmail.com




Information forwarded to debian-bugs-dist@lists.debian.org, Debian MySQL Maintainers <pkg-mysql-maint@lists.alioth.debian.org>:
Bug#426353; Package mysql-server-5.0. Full text and rfc822 format available.

Acknowledgement sent to Christian Hammers <ch@debian.org>:
Extra info received and forwarded to list. Copy sent to Debian MySQL Maintainers <pkg-mysql-maint@lists.alioth.debian.org>. Full text and rfc822 format available.

Message #20 received at 426353@bugs.debian.org (full text, mbox):

From: Christian Hammers <ch@debian.org>
To: 426353@bugs.debian.org
Cc: Debian Bug Control <control@bugs.debian.org>
Subject: Re: MySQL security bug
Date: Sat, 23 Jun 2007 15:22:24 +0200
tags 426353 + security pending
retitle 426353 CVE-2007-2583: DoS in item_cmpfunc.cc (MySQL#27513)
fixed 426353 5.0.40
stop

An upload for stable-security has been prepared by Sean on May 28 and
the Security Team has been reminded on Jun 18.

bye,

-christian-



Tags added: security, pending Request was from Christian Hammers <ch@debian.org> to control@bugs.debian.org. (Sat, 23 Jun 2007 13:27:07 GMT) Full text and rfc822 format available.

Changed Bug title to `CVE-2007-2583: DoS in item_cmpfunc.cc (MySQL#27513)' from `mysql-server-5.0: Please add patch for this bug to stable mysql-5.0 server. http://bugs.mysql.com/bug.php?id=27513'. Request was from Christian Hammers <ch@debian.org> to control@bugs.debian.org. (Sat, 23 Jun 2007 13:27:08 GMT) Full text and rfc822 format available.

Bug marked as fixed in version 5.0.40. Request was from Christian Hammers <ch@debian.org> to control@bugs.debian.org. (Sat, 23 Jun 2007 13:27:09 GMT) Full text and rfc822 format available.

Tags added: pending Request was from Christian Hammers <ch@alioth.debian.org> to control@bugs.debian.org. (Tue, 06 Nov 2007 23:00:07 GMT) Full text and rfc822 format available.

Tags added: pending Request was from Norbert Tretkowski <norbert@tretkowski.de> to control@bugs.debian.org. (Mon, 19 Nov 2007 20:51:03 GMT) Full text and rfc822 format available.

Bug marked as fixed in version 5.0.32-7etch2. Request was from Norbert Tretkowski <norbert@tretkowski.de> to control@bugs.debian.org. (Sat, 02 Feb 2008 10:27:02 GMT) Full text and rfc822 format available.

Tags removed: pending Request was from Norbert Tretkowski <nobse@debian.org> to control@bugs.debian.org. (Sat, 22 Mar 2008 12:33:08 GMT) Full text and rfc822 format available.

Reply sent to Norbert Tretkowski <norbert@tretkowski.de>:
You have taken responsibility. Full text and rfc822 format available.

Notification sent to Okulov Vitaliy <vitaliy.okulov@gmail.com>:
Bug acknowledged by developer. Full text and rfc822 format available.

Message #39 received at 426353-done@bugs.debian.org (full text, mbox):

From: Norbert Tretkowski <norbert@tretkowski.de>
To: 426353-done@bugs.debian.org
Subject: Fixed
Date: Sat, 22 Mar 2008 13:38:55 +0100
Version: 5.0.41-1





Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Mon, 16 Jun 2008 07:39:56 GMT) Full text and rfc822 format available.

Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Thu Apr 17 02:09:19 2014; Machine Name: beach.debian.org

Debian Bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.