Date: Thu, 9 Mar 2000 15:28:02 -0800 (PST)
From: Katie Moussouris k8e@mail.turbolinux.com
To: tl-security-announce@turbolinux.com
Subject: [TL-Security-Announce] MySQL-3.22.27-5 and earlier
TLSA200006-1
TurboLinux Security Announcement
Package: MySQL-3.22.27-5 and earlier
Date: Thu Mar 9 13:48:52 PST 2000
Affected TurboLinux versions: 6.0.2 and earlier
Vulnerability Type: remote, possible MySQL DoS
TurboLinux Advisory ID#: TLSA200006-1
BugTraq ID#: 975
Credits: This vulnerability was posted to the Bugtraq mailing list
on February 8, 2000 by Robert van der Meulen .
A security hole was discovered in the package mentioned above.
Please update the package in your installation as soon as possible
or disable the service.
1. Problem Summary
The MySQL database server (prior to 3.22.32) has a flawed
password authentication mechanism. Anyone who can connect to the
server can access databases without knowing an exact password. When
a check string of length one is passed to the server, only one
character is compared. There are only 32 possibilities for the
first character of the server-side check string.
2. Impact
An attacker will have all of the access rights of the database
user and may be able to read, add, or modify records. From Robert’s
original post: “This vulnerability also incorporates a MySQL DoS
attack, as the attacker can shutdown database servers and delete
data, if she logs in with the MySQL management account.”
3. Solution
Update the package from our ftp server by running the following
command:
rpm -Fv ftp_path_to_filename
Where ftp_path_to_filename is the following:
ftp://ftp.turbolinux.com/pub/updates/6.0/security/MySQL-3.22.32-1.i386.rpm
The source rpm can be downloaded here:
ftp://ftp.turbolinux.com/pub/updates/6.0/SRPMS/MySQL-3.22.32-1.src.rpm
**Note: You must rebuild and install the rpm if you choose to
download and install the srpm. Simply installing the srpm alone
WILL NOT CLOSE THE SECURITY HOLE.
Please verify the md5 checksum of the update before you
install:
MD5 sum Package Name
590e3085c4c281e44cfc807d0c05439d MySQL-3.22.32-1.i386.rpm 3eaf76a010ce4482cf9d55643485b9c3 MySQL-3.22.32-1.src.rpm
You can find more updates on our ftp server:
ftp://ftp.turbolinux.com/pub/updates/6.0/security/
for TL6.0 Workstation and Server security updates
ftp://ftp.turbolinux.com/pub/updates/4.0/security/
for TL4.0 Workstation and Server security updates
Our webpage for security announcements:
http://www.turbolinux.com/security
If you want to report vulnerabilities, please contact: rt-security@turbolinux.com