Summary
The remote host is missing an update to mysql-dfsg-4.1 announced via advisory DSA 783-1.
Eric Romang discovered a temporary file vulnerability in a script accompanied with MySQL, a popular database, that allows an attacker to execute arbitrary SQL commands when the server is installed or updated.
The old stable distribution (woody) as well as mysql-dfsg are not affected by this problem.
Solution
For the stable distribution (sarge) this problem has been fixed in version 4.1_4.1.11a-4sarge1.
For the unstable distribution (sid) this problem has been fixed in version 4.1.12 for mysql-dfsg-4.1 and 5.0.11beta-3 of mysql-dfsg-5.0.
We recommend that you upgrade your mysql packages.
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20783-1
Severity
Classification
-
CVE CVE-2005-1636 -
CVSS Base Score: 4.6
AV:L/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities