[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

UNIRAS Brief - 395/06 - Two Red Hat Security Advisories:



-----BEGIN PGP SIGNED MESSAGE-----

- ----------------------------------------------------------------------------------
   UNIRAS (UK Govt CERT) Briefing Notice - 395/06 dated 12.06.06  Time: 15:25  
  UNIRAS is part of NISCC (National Infrastructure Security Co-ordination Centre)
- ---------------------------------------------------------------------------------- 
  UNIRAS material is also available from its website at www.uniras.gov.uk and
         Information about NISCC is available from www.niscc.gov.uk
- ----------------------------------------------------------------------------------

Title
=====

Two Red Hat Security Advisories:

1. RHSA-2006:0486-01 - Moderate: mailman security update
      
2. RHSA-2006:0544-01 - Important: mysql security update

Detail
====== 

1. A flaw was found in the way Mailman handles MIME multipart messages. An
attacker could send a carefully crafted MIME multipart email message to a
mailing list run by Mailman which would cause that particular mailing list
to stop working. (CVE-2006-0052)

2. MySQL is a multi-user, multi-threaded SQL database server. MySQL is a
client/server implementation consisting of a server daemon (mysqld) and
many different client programs and libraries.



1.




- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- - ---------------------------------------------------------------------
                   Red Hat Security Advisory

Synopsis:          Moderate: mailman security update
Advisory ID:       RHSA-2006:0486-01
Advisory URL:      https://rhn.redhat.com/errata/RHSA-2006-0486.html
Issue date:        2006-06-09
Updated on:        2006-06-09
Product:           Red Hat Enterprise Linux
CVE Names:         CVE-2006-0052 
- - ---------------------------------------------------------------------

1. Summary:

An updated mailman package that fixes a denial of service flaw is now
available for Red Hat Enterprise Linux 3 and 4.

This update has been rated as having moderate security impact by the Red
Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Desktop version 3 - i386, x86_64
Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64

3. Problem description:

Mailman is software to help manage email discussion lists.

A flaw was found in the way Mailman handles MIME multipart messages. An
attacker could send a carefully crafted MIME multipart email message to a
mailing list run by Mailman which would cause that particular mailing list
to stop working. (CVE-2006-0052)

Users of Mailman should upgrade to this updated package, which contains
backported patches to correct this issue.

4. Solution:

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

This update is available via Red Hat Network.  To use Red Hat Network,
launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.

5. Bug IDs fixed (http://bugzilla.redhat.com/):

187420 - CVE-2006-0052 Mailman DoS

6. RPMs required:

Red Hat Enterprise Linux AS version 3:

SRPMS:
ftp://updates.redhat.com/enterprise/3AS/en/os/SRPMS/mailman-2.1.5.1-25.rhel3.5.src.rpm
864b23ce9d7bb6ec67e1925e727b00a1  mailman-2.1.5.1-25.rhel3.5.src.rpm

i386:
1f8675edb008914d72c17ac208778ce8  mailman-2.1.5.1-25.rhel3.5.i386.rpm
5591118fdeb23c8f7ab773ecc89b2d64  mailman-debuginfo-2.1.5.1-25.rhel3.5.i386.rpm

ia64:
dea1f57a4cab00421c7e733abce56d0a  mailman-2.1.5.1-25.rhel3.5.ia64.rpm
d626620c55ce2d6be83ede96d2b52b2a  mailman-debuginfo-2.1.5.1-25.rhel3.5.ia64.rpm

ppc:
28603ff74e71bf42a65a642219ac2c12  mailman-2.1.5.1-25.rhel3.5.ppc.rpm
2092db336ea3383b409ae08b72805c3c  mailman-debuginfo-2.1.5.1-25.rhel3.5.ppc.rpm

s390:
8b71da905859dda6df957227d7813f73  mailman-2.1.5.1-25.rhel3.5.s390.rpm
750eb1cb63a4bb4e10fc43b0c13df8e4  mailman-debuginfo-2.1.5.1-25.rhel3.5.s390.rpm

s390x:
0d6b38a5ba6d707bf7be2c97e5d5f697  mailman-2.1.5.1-25.rhel3.5.s390x.rpm
dd4ba23b250a06c22b92cf944de05021  mailman-debuginfo-2.1.5.1-25.rhel3.5.s390x.rpm

x86_64:
cb3afd6302189d2141198f6569405ab2  mailman-2.1.5.1-25.rhel3.5.x86_64.rpm
b599a1cc3684547547eafca41c4f0aed  mailman-debuginfo-2.1.5.1-25.rhel3.5.x86_64.rpm

Red Hat Desktop version 3:

SRPMS:
ftp://updates.redhat.com/enterprise/3desktop/en/os/SRPMS/mailman-2.1.5.1-25.rhel3.5.src.rpm
864b23ce9d7bb6ec67e1925e727b00a1  mailman-2.1.5.1-25.rhel3.5.src.rpm

i386:
1f8675edb008914d72c17ac208778ce8  mailman-2.1.5.1-25.rhel3.5.i386.rpm
5591118fdeb23c8f7ab773ecc89b2d64  mailman-debuginfo-2.1.5.1-25.rhel3.5.i386.rpm

x86_64:
cb3afd6302189d2141198f6569405ab2  mailman-2.1.5.1-25.rhel3.5.x86_64.rpm
b599a1cc3684547547eafca41c4f0aed  mailman-debuginfo-2.1.5.1-25.rhel3.5.x86_64.rpm

Red Hat Enterprise Linux ES version 3:

SRPMS:
ftp://updates.redhat.com/enterprise/3ES/en/os/SRPMS/mailman-2.1.5.1-25.rhel3.5.src.rpm
864b23ce9d7bb6ec67e1925e727b00a1  mailman-2.1.5.1-25.rhel3.5.src.rpm

i386:
1f8675edb008914d72c17ac208778ce8  mailman-2.1.5.1-25.rhel3.5.i386.rpm
5591118fdeb23c8f7ab773ecc89b2d64  mailman-debuginfo-2.1.5.1-25.rhel3.5.i386.rpm

ia64:
dea1f57a4cab00421c7e733abce56d0a  mailman-2.1.5.1-25.rhel3.5.ia64.rpm
d626620c55ce2d6be83ede96d2b52b2a  mailman-debuginfo-2.1.5.1-25.rhel3.5.ia64.rpm

x86_64:
cb3afd6302189d2141198f6569405ab2  mailman-2.1.5.1-25.rhel3.5.x86_64.rpm
b599a1cc3684547547eafca41c4f0aed  mailman-debuginfo-2.1.5.1-25.rhel3.5.x86_64.rpm

Red Hat Enterprise Linux WS version 3:

SRPMS:
ftp://updates.redhat.com/enterprise/3WS/en/os/SRPMS/mailman-2.1.5.1-25.rhel3.5.src.rpm
864b23ce9d7bb6ec67e1925e727b00a1  mailman-2.1.5.1-25.rhel3.5.src.rpm

i386:
1f8675edb008914d72c17ac208778ce8  mailman-2.1.5.1-25.rhel3.5.i386.rpm
5591118fdeb23c8f7ab773ecc89b2d64  mailman-debuginfo-2.1.5.1-25.rhel3.5.i386.rpm

ia64:
dea1f57a4cab00421c7e733abce56d0a  mailman-2.1.5.1-25.rhel3.5.ia64.rpm
d626620c55ce2d6be83ede96d2b52b2a  mailman-debuginfo-2.1.5.1-25.rhel3.5.ia64.rpm

x86_64:
cb3afd6302189d2141198f6569405ab2  mailman-2.1.5.1-25.rhel3.5.x86_64.rpm
b599a1cc3684547547eafca41c4f0aed  mailman-debuginfo-2.1.5.1-25.rhel3.5.x86_64.rpm

Red Hat Enterprise Linux AS version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4AS/en/os/SRPMS/mailman-2.1.5.1-34.rhel4.3.src.rpm
710bda1e3e2d327750b2e173e4f26ade  mailman-2.1.5.1-34.rhel4.3.src.rpm

i386:
d9ef371fe0bbfd5088458a66252fc85a  mailman-2.1.5.1-34.rhel4.3.i386.rpm
d845b291a05886a7e2747d69cd92c787  mailman-debuginfo-2.1.5.1-34.rhel4.3.i386.rpm

ia64:
e6f69b07fa7bcda1bd243c0ee9fc625f  mailman-2.1.5.1-34.rhel4.3.ia64.rpm
1fa4545391bdebbb8a2756f475534341  mailman-debuginfo-2.1.5.1-34.rhel4.3.ia64.rpm

ppc:
aac7cd4291f95b603ca1318844b8aa67  mailman-2.1.5.1-34.rhel4.3.ppc.rpm
83cdd5e4b505ce46fd720dcfb6a629b4  mailman-debuginfo-2.1.5.1-34.rhel4.3.ppc.rpm

s390:
fb24bfc7f51ce6078c0f2918485aa88f  mailman-2.1.5.1-34.rhel4.3.s390.rpm
00ad62057a06e026111c877ad93c8b7f  mailman-debuginfo-2.1.5.1-34.rhel4.3.s390.rpm

s390x:
d193fd7597c5f871f819865674c13c15  mailman-2.1.5.1-34.rhel4.3.s390x.rpm
f8dcab2a9ffd04fc13f4441035111406  mailman-debuginfo-2.1.5.1-34.rhel4.3.s390x.rpm

x86_64:
bff48be8cc1ca2adc29e50d80c274973  mailman-2.1.5.1-34.rhel4.3.x86_64.rpm
d0a2ba73d5d845a9799d0d86634dc866  mailman-debuginfo-2.1.5.1-34.rhel4.3.x86_64.rpm

Red Hat Enterprise Linux Desktop version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4Desktop/en/os/SRPMS/mailman-2.1.5.1-34.rhel4.3.src.rpm
710bda1e3e2d327750b2e173e4f26ade  mailman-2.1.5.1-34.rhel4.3.src.rpm

i386:
d9ef371fe0bbfd5088458a66252fc85a  mailman-2.1.5.1-34.rhel4.3.i386.rpm
d845b291a05886a7e2747d69cd92c787  mailman-debuginfo-2.1.5.1-34.rhel4.3.i386.rpm

x86_64:
bff48be8cc1ca2adc29e50d80c274973  mailman-2.1.5.1-34.rhel4.3.x86_64.rpm
d0a2ba73d5d845a9799d0d86634dc866  mailman-debuginfo-2.1.5.1-34.rhel4.3.x86_64.rpm

Red Hat Enterprise Linux ES version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4ES/en/os/SRPMS/mailman-2.1.5.1-34.rhel4.3.src.rpm
710bda1e3e2d327750b2e173e4f26ade  mailman-2.1.5.1-34.rhel4.3.src.rpm

i386:
d9ef371fe0bbfd5088458a66252fc85a  mailman-2.1.5.1-34.rhel4.3.i386.rpm
d845b291a05886a7e2747d69cd92c787  mailman-debuginfo-2.1.5.1-34.rhel4.3.i386.rpm

ia64:
e6f69b07fa7bcda1bd243c0ee9fc625f  mailman-2.1.5.1-34.rhel4.3.ia64.rpm
1fa4545391bdebbb8a2756f475534341  mailman-debuginfo-2.1.5.1-34.rhel4.3.ia64.rpm

x86_64:
bff48be8cc1ca2adc29e50d80c274973  mailman-2.1.5.1-34.rhel4.3.x86_64.rpm
d0a2ba73d5d845a9799d0d86634dc866  mailman-debuginfo-2.1.5.1-34.rhel4.3.x86_64.rpm

Red Hat Enterprise Linux WS version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4WS/en/os/SRPMS/mailman-2.1.5.1-34.rhel4.3.src.rpm
710bda1e3e2d327750b2e173e4f26ade  mailman-2.1.5.1-34.rhel4.3.src.rpm

i386:
d9ef371fe0bbfd5088458a66252fc85a  mailman-2.1.5.1-34.rhel4.3.i386.rpm
d845b291a05886a7e2747d69cd92c787  mailman-debuginfo-2.1.5.1-34.rhel4.3.i386.rpm

ia64:
e6f69b07fa7bcda1bd243c0ee9fc625f  mailman-2.1.5.1-34.rhel4.3.ia64.rpm
1fa4545391bdebbb8a2756f475534341  mailman-debuginfo-2.1.5.1-34.rhel4.3.ia64.rpm

x86_64:
bff48be8cc1ca2adc29e50d80c274973  mailman-2.1.5.1-34.rhel4.3.x86_64.rpm
d0a2ba73d5d845a9799d0d86634dc866  mailman-debuginfo-2.1.5.1-34.rhel4.3.x86_64.rpm

These packages are GPG signed by Red Hat for security.  Our key and 
details on how to verify the signature are available from
https://www.redhat.com/security/team/key/#package

7. References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0052
http://www.redhat.com/security/updates/classification/#moderate

8. Contact:

The Red Hat security contact is <secalert@xxxxxxxxxx>.  More contact
details at https://www.redhat.com/security/team/contact/

Copyright 2006 Red Hat, Inc.
- -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)

iD8DBQFEiZILXlSAg2UNWIIRAkDMAJwNBvGPXWyu0c7w0niSO1ujNxFjOQCgxXJM
diQaWeTVHFuspykIb7HqKJw=
=503R
- -----END PGP SIGNATURE-----



2.


- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- - ---------------------------------------------------------------------
                   Red Hat Security Advisory

Synopsis:          Important: mysql security update
Advisory ID:       RHSA-2006:0544-01
Advisory URL:      https://rhn.redhat.com/errata/RHSA-2006-0544.html
Issue date:        2006-06-09
Updated on:        2006-06-09
Product:           Red Hat Enterprise Linux
CVE Names:         CVE-2006-0903 CVE-2006-1516 CVE-2006-1517 
                   CVE-2006-2753 
- - ---------------------------------------------------------------------

1. Summary:

Updated mysql packages that fix multiple security flaws are now available.

This update has been rated as having important security impact by the Red Hat
Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64

3. Problem description:

MySQL is a multi-user, multi-threaded SQL database server. MySQL is a
client/server implementation consisting of a server daemon (mysqld) and
many different client programs and libraries.

A flaw was found in the way the MySQL mysql_real_escape() function escaped
strings when operating in a multibyte character encoding.  An attacker
could provide an application a carefully crafted string containing
invalidly-encoded characters which may be improperly escaped, leading to
the injection of malicious SQL commands. (CVE-2006-2753)

An information disclosure flaw was found in the way the MySQL server
processed malformed usernames. An attacker could view a small portion
of server memory by supplying an anonymous login username which was not
null terminated. (CVE-2006-1516)

An information disclosure flaw was found in the way the MySQL server
executed the COM_TABLE_DUMP command. An authenticated malicious user could
send a specially crafted packet to the MySQL server which returned
random unallocated memory. (CVE-2006-1517)

A log file obfuscation flaw was found in the way the mysql_real_query()
function creates log file entries. An attacker with the the ability to call
the mysql_real_query() function against a mysql server can obfuscate the
entry the server will write to the log file.  However, an attacker needed
to have complete control over a server in order to attempt this attack.
(CVE-2006-0903)

This update also fixes numerous non-security-related flaws, such as
intermittent authentication failures.

All users of mysql are advised to upgrade to these updated packages
containing MySQL version 4.1.20, which is not vulnerable to these issues.

4. Solution:

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

This update is available via Red Hat Network.  To use Red Hat Network,
launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.

5. Bug IDs fixed (http://bugzilla.redhat.com/):

183260 - CVE-2006-0903 Mysql log file obfuscation
183277 - Client error in mysql on updates when high concurrency
190743 - CVE-2006-1517 Mysql information leak
190863 - CVE-2006-1516 mysql anonymous login information leak
193827 - CVE-2006-2753 MySQL improper multibyte string escaping

6. RPMs required:

Red Hat Enterprise Linux AS version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4AS/en/os/SRPMS/mysql-4.1.20-1.RHEL4.1.src.rpm
a2f3a2d4debf79880185121dbbe44046  mysql-4.1.20-1.RHEL4.1.src.rpm

i386:
08a2cb1c1b6d0a017d1dd8b0e146d753  mysql-4.1.20-1.RHEL4.1.i386.rpm
4c64c56cf7cd7e51b8af1ddc0d7f9927  mysql-bench-4.1.20-1.RHEL4.1.i386.rpm
96ba397daa68548bb295892e42b09e33  mysql-debuginfo-4.1.20-1.RHEL4.1.i386.rpm
c8b580d2a1a92a11a2f493dba2b96159  mysql-devel-4.1.20-1.RHEL4.1.i386.rpm
8aa0d5a1d3600ff7896d82d69935aed3  mysql-server-4.1.20-1.RHEL4.1.i386.rpm

ia64:
08a2cb1c1b6d0a017d1dd8b0e146d753  mysql-4.1.20-1.RHEL4.1.i386.rpm
31f495c09ada1272043c2f20d51da60f  mysql-4.1.20-1.RHEL4.1.ia64.rpm
dd14f3e7d79bcb43249ac4ac8e1f0e94  mysql-bench-4.1.20-1.RHEL4.1.ia64.rpm
96ba397daa68548bb295892e42b09e33  mysql-debuginfo-4.1.20-1.RHEL4.1.i386.rpm
e620639f885eaf3be8c6c1d40c1940de  mysql-debuginfo-4.1.20-1.RHEL4.1.ia64.rpm
645a30fe7523fabb1dad211122c91696  mysql-devel-4.1.20-1.RHEL4.1.ia64.rpm
862dc1e3420a5701a6cfba70637b9fb0  mysql-server-4.1.20-1.RHEL4.1.ia64.rpm

ppc:
73930f1ecacdf0104a5fa0eb26991af5  mysql-4.1.20-1.RHEL4.1.ppc.rpm
fb6cd06215f42871c55040072bef98de  mysql-4.1.20-1.RHEL4.1.ppc64.rpm
324850079285509d584b626966f89843  mysql-bench-4.1.20-1.RHEL4.1.ppc.rpm
0f80ce0a2b0891a0aab431d9c5588d42  mysql-debuginfo-4.1.20-1.RHEL4.1.ppc.rpm
d26e8999933c2bc912a6527b787cc299  mysql-debuginfo-4.1.20-1.RHEL4.1.ppc64.rpm
217f143cc4e238fab9be84224e224635  mysql-devel-4.1.20-1.RHEL4.1.ppc.rpm
9030e10ce11abc622e8199a3b4556a98  mysql-server-4.1.20-1.RHEL4.1.ppc.rpm

s390:
ffcae0f612254941d5ad5456f0ac01ad  mysql-4.1.20-1.RHEL4.1.s390.rpm
4e73c481e7694d273855f11008297075  mysql-bench-4.1.20-1.RHEL4.1.s390.rpm
cd366cc29ed9e1a0ccbee71ff87e5885  mysql-debuginfo-4.1.20-1.RHEL4.1.s390.rpm
0c8cf2d8bbb3a612448715678ffdcd8d  mysql-devel-4.1.20-1.RHEL4.1.s390.rpm
dac602ffe37660b8e3c01ecfeb910337  mysql-server-4.1.20-1.RHEL4.1.s390.rpm

s390x:
ffcae0f612254941d5ad5456f0ac01ad  mysql-4.1.20-1.RHEL4.1.s390.rpm
63bae1479ea4798b2d0baa5478819402  mysql-4.1.20-1.RHEL4.1.s390x.rpm
739d66b027e6ba5a7826e7b039bc7060  mysql-bench-4.1.20-1.RHEL4.1.s390x.rpm
cd366cc29ed9e1a0ccbee71ff87e5885  mysql-debuginfo-4.1.20-1.RHEL4.1.s390.rpm
cba045f8922ce1337e6bebca5de72d9c  mysql-debuginfo-4.1.20-1.RHEL4.1.s390x.rpm
3463483049e38a6fbd4ee34f427ac869  mysql-devel-4.1.20-1.RHEL4.1.s390x.rpm
20870248905a1c3af1bf6b17688b5843  mysql-server-4.1.20-1.RHEL4.1.s390x.rpm

x86_64:
08a2cb1c1b6d0a017d1dd8b0e146d753  mysql-4.1.20-1.RHEL4.1.i386.rpm
3c3d997209f94f16c296ec9022f0ae56  mysql-4.1.20-1.RHEL4.1.x86_64.rpm
9247f09ee8067fb2e233948399c2ee19  mysql-bench-4.1.20-1.RHEL4.1.x86_64.rpm
96ba397daa68548bb295892e42b09e33  mysql-debuginfo-4.1.20-1.RHEL4.1.i386.rpm
9b83df74fbedf9922bfea831c7442e00  mysql-debuginfo-4.1.20-1.RHEL4.1.x86_64.rpm
6dd062482cf41bf37c426dbb7d5d19f7  mysql-devel-4.1.20-1.RHEL4.1.x86_64.rpm
3dc3e127614cc1d015ec43d34e5f66dd  mysql-server-4.1.20-1.RHEL4.1.x86_64.rpm

Red Hat Enterprise Linux Desktop version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4Desktop/en/os/SRPMS/mysql-4.1.20-1.RHEL4.1.src.rpm
a2f3a2d4debf79880185121dbbe44046  mysql-4.1.20-1.RHEL4.1.src.rpm

i386:
08a2cb1c1b6d0a017d1dd8b0e146d753  mysql-4.1.20-1.RHEL4.1.i386.rpm
4c64c56cf7cd7e51b8af1ddc0d7f9927  mysql-bench-4.1.20-1.RHEL4.1.i386.rpm
96ba397daa68548bb295892e42b09e33  mysql-debuginfo-4.1.20-1.RHEL4.1.i386.rpm
c8b580d2a1a92a11a2f493dba2b96159  mysql-devel-4.1.20-1.RHEL4.1.i386.rpm
8aa0d5a1d3600ff7896d82d69935aed3  mysql-server-4.1.20-1.RHEL4.1.i386.rpm

x86_64:
08a2cb1c1b6d0a017d1dd8b0e146d753  mysql-4.1.20-1.RHEL4.1.i386.rpm
3c3d997209f94f16c296ec9022f0ae56  mysql-4.1.20-1.RHEL4.1.x86_64.rpm
9247f09ee8067fb2e233948399c2ee19  mysql-bench-4.1.20-1.RHEL4.1.x86_64.rpm
96ba397daa68548bb295892e42b09e33  mysql-debuginfo-4.1.20-1.RHEL4.1.i386.rpm
9b83df74fbedf9922bfea831c7442e00  mysql-debuginfo-4.1.20-1.RHEL4.1.x86_64.rpm
6dd062482cf41bf37c426dbb7d5d19f7  mysql-devel-4.1.20-1.RHEL4.1.x86_64.rpm
3dc3e127614cc1d015ec43d34e5f66dd  mysql-server-4.1.20-1.RHEL4.1.x86_64.rpm

Red Hat Enterprise Linux ES version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4ES/en/os/SRPMS/mysql-4.1.20-1.RHEL4.1.src.rpm
a2f3a2d4debf79880185121dbbe44046  mysql-4.1.20-1.RHEL4.1.src.rpm

i386:
08a2cb1c1b6d0a017d1dd8b0e146d753  mysql-4.1.20-1.RHEL4.1.i386.rpm
4c64c56cf7cd7e51b8af1ddc0d7f9927  mysql-bench-4.1.20-1.RHEL4.1.i386.rpm
96ba397daa68548bb295892e42b09e33  mysql-debuginfo-4.1.20-1.RHEL4.1.i386.rpm
c8b580d2a1a92a11a2f493dba2b96159  mysql-devel-4.1.20-1.RHEL4.1.i386.rpm
8aa0d5a1d3600ff7896d82d69935aed3  mysql-server-4.1.20-1.RHEL4.1.i386.rpm

ia64:
08a2cb1c1b6d0a017d1dd8b0e146d753  mysql-4.1.20-1.RHEL4.1.i386.rpm
31f495c09ada1272043c2f20d51da60f  mysql-4.1.20-1.RHEL4.1.ia64.rpm
dd14f3e7d79bcb43249ac4ac8e1f0e94  mysql-bench-4.1.20-1.RHEL4.1.ia64.rpm
96ba397daa68548bb295892e42b09e33  mysql-debuginfo-4.1.20-1.RHEL4.1.i386.rpm
e620639f885eaf3be8c6c1d40c1940de  mysql-debuginfo-4.1.20-1.RHEL4.1.ia64.rpm
645a30fe7523fabb1dad211122c91696  mysql-devel-4.1.20-1.RHEL4.1.ia64.rpm
862dc1e3420a5701a6cfba70637b9fb0  mysql-server-4.1.20-1.RHEL4.1.ia64.rpm

x86_64:
08a2cb1c1b6d0a017d1dd8b0e146d753  mysql-4.1.20-1.RHEL4.1.i386.rpm
3c3d997209f94f16c296ec9022f0ae56  mysql-4.1.20-1.RHEL4.1.x86_64.rpm
9247f09ee8067fb2e233948399c2ee19  mysql-bench-4.1.20-1.RHEL4.1.x86_64.rpm
96ba397daa68548bb295892e42b09e33  mysql-debuginfo-4.1.20-1.RHEL4.1.i386.rpm
9b83df74fbedf9922bfea831c7442e00  mysql-debuginfo-4.1.20-1.RHEL4.1.x86_64.rpm
6dd062482cf41bf37c426dbb7d5d19f7  mysql-devel-4.1.20-1.RHEL4.1.x86_64.rpm
3dc3e127614cc1d015ec43d34e5f66dd  mysql-server-4.1.20-1.RHEL4.1.x86_64.rpm

Red Hat Enterprise Linux WS version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4WS/en/os/SRPMS/mysql-4.1.20-1.RHEL4.1.src.rpm
a2f3a2d4debf79880185121dbbe44046  mysql-4.1.20-1.RHEL4.1.src.rpm

i386:
08a2cb1c1b6d0a017d1dd8b0e146d753  mysql-4.1.20-1.RHEL4.1.i386.rpm
4c64c56cf7cd7e51b8af1ddc0d7f9927  mysql-bench-4.1.20-1.RHEL4.1.i386.rpm
96ba397daa68548bb295892e42b09e33  mysql-debuginfo-4.1.20-1.RHEL4.1.i386.rpm
c8b580d2a1a92a11a2f493dba2b96159  mysql-devel-4.1.20-1.RHEL4.1.i386.rpm
8aa0d5a1d3600ff7896d82d69935aed3  mysql-server-4.1.20-1.RHEL4.1.i386.rpm

ia64:
08a2cb1c1b6d0a017d1dd8b0e146d753  mysql-4.1.20-1.RHEL4.1.i386.rpm
31f495c09ada1272043c2f20d51da60f  mysql-4.1.20-1.RHEL4.1.ia64.rpm
dd14f3e7d79bcb43249ac4ac8e1f0e94  mysql-bench-4.1.20-1.RHEL4.1.ia64.rpm
96ba397daa68548bb295892e42b09e33  mysql-debuginfo-4.1.20-1.RHEL4.1.i386.rpm
e620639f885eaf3be8c6c1d40c1940de  mysql-debuginfo-4.1.20-1.RHEL4.1.ia64.rpm
645a30fe7523fabb1dad211122c91696  mysql-devel-4.1.20-1.RHEL4.1.ia64.rpm
862dc1e3420a5701a6cfba70637b9fb0  mysql-server-4.1.20-1.RHEL4.1.ia64.rpm

x86_64:
08a2cb1c1b6d0a017d1dd8b0e146d753  mysql-4.1.20-1.RHEL4.1.i386.rpm
3c3d997209f94f16c296ec9022f0ae56  mysql-4.1.20-1.RHEL4.1.x86_64.rpm
9247f09ee8067fb2e233948399c2ee19  mysql-bench-4.1.20-1.RHEL4.1.x86_64.rpm
96ba397daa68548bb295892e42b09e33  mysql-debuginfo-4.1.20-1.RHEL4.1.i386.rpm
9b83df74fbedf9922bfea831c7442e00  mysql-debuginfo-4.1.20-1.RHEL4.1.x86_64.rpm
6dd062482cf41bf37c426dbb7d5d19f7  mysql-devel-4.1.20-1.RHEL4.1.x86_64.rpm
3dc3e127614cc1d015ec43d34e5f66dd  mysql-server-4.1.20-1.RHEL4.1.x86_64.rpm

These packages are GPG signed by Red Hat for security.  Our key and 
details on how to verify the signature are available from
https://www.redhat.com/security/team/key/#package

7. References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0903
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1516
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1517
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2753
http://lists.mysql.com/announce/364
http://www.redhat.com/security/updates/classification/#important

8. Contact:

The Red Hat security contact is <secalert@xxxxxxxxxx>.  More contact
details at https://www.redhat.com/security/team/contact/

Copyright 2006 Red Hat, Inc.
- -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)

iD8DBQFEiZIkXlSAg2UNWIIRAub7AJ9VTr8g04Mr7jMmGyFYzBD85hPp1gCfSxGv
S69DIVl90FSFSdN2ogVTqnc=
=Td5w
- -----END PGP SIGNATURE-----




- ----------------------------------------------------------------------------------

For additional information or assistance, please contact the HELP Desk by 
telephone or Not Protectively Marked information may be sent via 
EMail to: uniras@xxxxxxxxxxxx

Office Hours:
Mon - Fri: 08:30 - 17:00 Hrs
Tel: +44 (0) 870 487 0748 Ext 4511
Fax: +44 (0) 870 487 0749

Outside of Office Hours:
On Call Duty Officer:
Tel: +44 (0) 870 487 0748 and follow the prompts

- ----------------------------------------------------------------------------------
UNIRAS wishes to acknowledge the contributions of Red Hat for the information 
contained in this Briefing. 
- ----------------------------------------------------------------------------------
This Briefing contains the information released by the original author. Some 
of the information may have changed since it was released. If the vulnerability 
affects you, it may be prudent to retrieve the advisory from the site of the
original source to ensure that you receive the most current information concerning 
that problem.

Reference to any specific commercial product, process, or service by trade 
name, trademark manufacturer, or otherwise, does not constitute or imply 
its endorsement, recommendation, or favouring by UNIRAS or NISCC.  The views 
and opinions of authors expressed within this notice shall not be used for 
advertising or product endorsement purposes.

Neither UNIRAS or NISCC shall also accept responsibility for any errors 
or omissions contained within this briefing notice. In particular, they shall 
not be liable for any loss or damage whatsoever, arising from or in connection 
with the usage of information contained within this notice.

UNIRAS is a member of the Forum of Incident Response and Security Teams (FIRST) 
and has contacts with other international Incident Response Teams (IRTs) in 
order to foster cooperation and coordination in incident prevention, to prompt 
rapid reaction to incidents, and to promote information sharing amongst its 
members and the community at large. 
- ----------------------------------------------------------------------------------
<End of UNIRAS Briefing>

-----BEGIN PGP SIGNATURE-----
Version: PGP 8.1

iQCVAwUBRI14N4pao72zK539AQHG8QP/Tv5u14XoXofMEIuzv0r5THL9hnQ5J3hW
7awQ+xWUsJslhru1yyEBIFdQanIotd8CQeHqgQX0hNCPCqoCVSngTIMvqAWeIXFg
0KGO3gzd5JfZ5l4W9kFRVALdW2jWHH9vGUW/VbqOF7WGkO1kcJYaKOr6miMuBH7s
NlO6Z78XzLw=
=wQ9a
-----END PGP SIGNATURE-----


______________________________________________________________________
This email has been scanned by the MessageLabs Email Security System.
For more information please visit http://www.messagelabs.com/email 
______________________________________________________________________

______________________________________________________________________
This email has been scanned by the MessageLabs Email Security System.
For more information please visit http://www.messagelabs.com/email 
______________________________________________________________________