copyright | disclaimer | privacy | contact  
Australia's Leading Computer Emergency Response Team
 
Search this site

 
On this site

 > HOME
 > About AusCERT
 > Membership
 > Contact Us
 > PKI Services
 > Publications
 > Sec. Bulletins
 > Conferences
 > News & Media
 > Services
 > Web Log
 > Site Map
 > Site Help
 > Member login





 

ESB-2005.0610 -- MySQL 4.1.13a binaries now available -- fix static zlib denial of service

Date: 05 August 2005
References: ESB-2005.0577  

Click here for printable version
Click here for PGP verifiable version
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

===========================================================================
             AUSCERT External Security Bulletin Redistribution

           ESB-2005.0610 -- MySQL 4.1.13a binaries now available
                     fix static zlib denial of service
                               5 August 2005

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           MySQL 4.1.13 and prior
Publisher:         MySQL
Operating System:  Windows
                   HP-UX (PA/RISC and IA64)
                   Mac OS X 10.4 (64 bit only)
                   AIX 5.2/4.3
                   Linux/s390
Impact:            Denial of Service
Access:            Remote/Unauthenticated
CVE Names:         CAN-2005-1849

Ref:               ESB-2005.0577

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hello,

The MySQL 4.1.13 release included a fix to resolve a potential security
vulnerability in the zlib compression library (CAN-2005-2096) that is bundled
with the MySQL distribution. Very shortly afterwards, an additional potential
zlib security flaw was discovered and fixed - the issue is tracked by the Mitre
CVE ID CAN-2005-1849. However, this second fix appeared too late for inclusion
in the initial MySQL 4.1.13 release.

Even though zlib is included in the MySQL sources, most binary builds
distributed by MySQL actually are not statically linked against it by default.

On most platforms, MySQL is linked dynamically to the shared zlib library
provided by the operating system. This means that it's usually sufficient to
update the zlib library and restart MySQL to resolve this issue. Many OS
vendors have provided zlib updates by now.

For those platforms were the binaries are linked statically against zlib and
that were affected by this second vulnerabilty, we have now published updated
binaries on our download pages. The source archive was updated as well.

The MySQL binaries for the following platforms are affected and have been
updated to version 4.1.13a:

 - Microsoft Windows
 - HPUX 11.00/11.11 (PA/RISC)
 - HPUX 11.23 (IA64)
 - Mac OS X 10.4 (64bit only)
 - IBM AIX 5.2/4.3
 - Linux/s390

This is the same code base as the 4.1.13 release with just one additional patch
to resolve the security issue tracked by CAN-2005-1849. The source and binaries
are now available for Download from http://dev.mysql.com/downloads/mysql/4.1.html
and mirror sites. Even though we are currently not aware of any program that is
actually capable of exploiting this zlib vulnerability within MySQL, we would
like to encourage our users to make sure they update to this version as soon as
possible.

Bye,
	LenZ
- - -- 
 Lenz Grimmer <lenz@mysql.com>
 Senior Production Engineer
 MySQL GmbH, http://www.mysql.de/
 Hamburg, Germany
 Are you MySQL certified?  http://www.mysql.com/certification/
- -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.0 (GNU/Linux)
Comment: For info see http://quantumlab.net/pine_privacy_guard/

iD8DBQFC8m7lSVDhKrJykfIRAnQBAJ0VL9oULqKWsp7DW7MChM3gqAGOuACfQq+N
ePZqTR4/+IGMT6dOXqzLq2Y=
=SI7n
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        http://www.auscert.org.au/render.html?cid=1980

If you believe that your computer system has been compromised or attacked in 
any way, we encourage you to let us know by completing the secure National IT 
Incident Reporting Form at:

        http://www.auscert.org.au/render.html?it=3192

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================

-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQCVAwUBQvKxGSh9+71yA2DNAQKqOQP+J976KmmrNhM6h/91j9DSh/FWVNBS5PyF
is6lkUYo+8N0jK2PovsIk95qR2vKuRzEW1MNoSolOR87r2U2QP90dNJzxSGKS/HO
hWcUmIZymc9W9ANS8gmH420tHENV1t9Qnydodf1evOvIHS6XCGh0j9Pw5R602geU
INf1HvmlNMc=
=1i9O
-----END PGP SIGNATURE-----