[Secure-testing-commits] r694 - sarge-checks/CAN

Moritz Muehlenhoff jmm-guest@costa.debian.org
Thu, 31 Mar 2005 06:27:52 +0000


Author: jmm-guest
Date: 2005-03-31 06:27:49 +0000 (Thu, 31 Mar 2005)
New Revision: 694

Modified:
   sarge-checks/CAN/list
Log:
MySQL privilege escalation.


Modified: sarge-checks/CAN/list
===================================================================
--- sarge-checks/CAN/list	2005-03-31 00:05:24 UTC (rev 693)
+++ sarge-checks/CAN/list	2005-03-31 06:27:49 UTC (rev 694)
@@ -4205,8 +4205,8 @@
 CAN-2004-0958 (php_variables.c in PHP before 5.0.2 allows remote attackers to read ...)
 	- php4 4.3.9
 CAN-2004-0957 (Unknown vulnerability in MySQL 3.23.58 and earlier, when a local user ...)
-	- mysql-dfsg 3.23.58
-	- mysql 3.23.58
+	- mysql-dfsg-4.1 4.1.10a-6
+	- mysql-dfsg 4.0.24-5
 CAN-2004-0956 (MySQL before 4.0.20 allows remote attackers to cause a denial of ...)
 	NOTE: not vulnerable according to http://www.debian.org/security/nonvulns-sarge
 CAN-2004-0955