Web Hosting Talk







View Full Version : ATTENTION! Mysql root exploit!


microsol
05-05-2003, 07:21 PM
Security Advisory - RHSA-2003:093-14
------------------------------------------------------------------------------
Summary:
Updated MySQL packages fix vulnerabilities

Updated MySQL server packages fix both a double-free security
vulnerability and a root exploit security vulnerability.

[Updated 1 May 2003]
Added updated packages for Red Hat Linux 9, which is vulnerable to
CAN-2003-0150.

Description:
MySQL is a multi-user, multi-threaded SQL database server.

A double-free vulnerability in mysqld, for MySQL before version 3.23.55,
allows attackers with MySQL access to cause a denial of service (crash) by
creating a carefully crafted client application. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2003-0073 to this issue.

MySQL 3.23.55 and earlier creates world-writable files and allows mysql
users to gain root privileges by using the "SELECT * INFO OUTFILE" operator
to overwrite a configuration file and cause mysql to run as root upon
restart. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the name CAN-2003-0150 to this issue.

All users are advised to upgrade to MySQL 3.23.56 contained within this
errata which is not vulnerable to these issues.

In addition to the security fixes, these erratum packages contain a
thread safe client library (libmysqlclient_r).

References:
http://www.mysql.com/doc/en/News-3.23.55.html
http://www.mysql.com/doc/en/News-3.23.56.html

RogelioH
05-05-2003, 07:48 PM
This is nothing new, but thank you for the warning.

microsol
05-05-2003, 08:17 PM
You got this advisory a month ago, right? :rolleyes:

Annette
05-05-2003, 08:43 PM
Elevation to run mySQL as root in 3.23.55? About two months old, actually, since it was discussed back around the first week of March on Bugtraq and security notices/updated rpms were available by end of March by the latest. This is an update for the following:

[Updated 1 May 2003]
Added updated packages for Red Hat Linux 9, which is vulnerable to CAN-2003-0150.

IGobyTerry
05-05-2003, 08:56 PM
I just got that in my email too. I'd assume mySQL 4 would be safe from this exploit then.

sprintserve
05-05-2003, 11:32 PM
yes. Mysql 4 would be safe from this exploit

bitserve
05-05-2003, 11:48 PM
I think that red hat was just announcing the availability of an rpm to fix the problem.

AFewtrell
05-06-2003, 05:02 AM
I remember upgrading mysql to 3.23.56 like a month ago because of this same exploit. :X

sprintserve
05-06-2003, 05:07 AM
You remember right. As pointed out by Annette, this is for Redhat 9.0 which must have shipped with an old version of Mysql.

AFewtrell
05-06-2003, 05:09 AM
Bad redhat, No cookie!

microsol
05-06-2003, 05:11 AM
Not only for RH9. This also applies to people running Plesk standard for example. Anyway, there are LOTS of ppl on this board not having a clue that they run an exploitable version of MySQL.

AFewtrell
05-06-2003, 05:13 AM
I think the only non uptodate software I have right now is phpmyadmin :X

sprintserve
05-06-2003, 05:14 AM
That's true too. But the specific advisory mentioned was with respect to RH 9.