The CentOS team has been looking at the issue called out in these stories:

http://threatpost.com/en_us/blogs/trivial-password-flaw-leaves-mysql-databases-exposed-061112

http://arstechnica.com/information-technology/2012/06/security-flaw-in-mysql-mariadb-allows-access-with-any-password-just-keep-submitting-it/

http://www.net-security.org/secworld.php?id=13076

According to the upstream provider EL4, EL5 and EL6 are not impacted by
the above issue:

https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-2122

Thanks,
Johnny Hughes

Attachment: signature.asc
Description: OpenPGP digital signature

_______________________________________________
CentOS mailing list
CentOS@centos.org
http://lists.centos.org/mailman/listinfo/centos

Reply via email to