Branches for Breezy

Name Status Last Modified Last Commit
lp://staging/ubuntu/breezy/mysql-dfsg 1 Development 2009-09-29 02:04:33 UTC
2. * SECURITY UPDATE: Fix privilege esca...

Author: Martin Pitt
Revision Date: 2005-09-09 17:52:31 UTC

* SECURITY UPDATE: Fix privilege escalation.
* Add debian/patches/52_CAN-2005-2558_init_syms_functionnames.dpatch:
  - Declare function name buffer to be big enough for the maximum possible
    function name to avoid buffer overflow. This could be exploited only by
    users who have the privilege to create functions.
* References:
  CAN-2005-2558
  http://lists.grok.org.uk/pipermail/full-disclosure/2005-August/035845.html
  http://bugs.debian.org/322133
  Ubuntu #13675

lp://staging/ubuntu/breezy-security/mysql-dfsg 1 Development 2009-07-20 08:36:15 UTC
5. * Replace 53_ignore_null_characters.d...

Author: Martin Pitt
Revision Date: 2006-05-15 11:18:05 UTC

* Replace 53_ignore_null_characters.dpatch with
  53_CVE-2006-0903_logging_bypass.dpatch: Do not simply ignore NUL
  characters in comments, but modify the logging function instead to log
  everything including the NULs.
* Thanks to Sean Finney and Christian Hammers for pointing this out and for
  supplying the patch.
* Add CVE number to 4.0.21-1 changelog.

12 of 2 results