Bugtraq mailing list archives

Re: potential vulnerability of mysqld running with root privileges (can be used as good DoS or r00t expoloit)


From: Trond Eivind Glomsrød <teg () REDHAT COM>
Date: Tue, 20 Mar 2001 16:34:29 -0500

"Pavlov, Lesha" <lesha () nn ru> writes:

Vulnerable versions:
This DoS/exploit tested on mysql-3.20.32a but i see another versions of
mysql also vulnerabile.

This could affect our RPMs for Red Hat PowerTools 6.1 and 6.2, which
used an ancient version of MySQL: It was the only version of MySQL
with a free license (we were allowed todistribute newer versions, but
chose not to because of their license).

The one shipped with Red Hat Linux 7, after MySQL changed their
standard license, is not affected as they don't run as root.

--
Trond Eivind Glomsrød
Red Hat, Inc.


Current thread: