Package: mysql-server
Version: 3.23.49-8.15 4.0.24-10sarge2
Severity: grave
Tags: security

A query like "select str_to_date( 1, NULL );" crashes mysqld.
This affects:
  Woody: mysql-server           3.23.x
  Sarge: mysql-server           4.0.x
  Sarge: mysql-server-4.1       4.1.x
Unstable/Testing is already fixed.

We are already preparing a DSA for Woody and Sarge.

References:
  http://seclists.org/lists/fulldisclosure/2006/Jun/0434.html
  http://bugs.mysql.com/bug.php?id=15828

bye,

-christan-



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to