Bug#296674: [CAN-2004-0957] i believe this patch should do it...

2005-03-20 Thread sean finney
hey folks, On Fri, Mar 18, 2005 at 04:33:52PM +0100, Martin Schulze wrote: > sean finney wrote: > > On Fri, Mar 11, 2005 at 09:39:10AM +0100, Christian Hammers wrote: > > > Wasn't it the one where a privilege granted to "table_name" also grants > > > rights on "tableXname", "tableYname" as '_' was

Bug#296674: [CAN-2004-0957] i believe this patch should do it...

2005-03-20 Thread Christian Hammers
Hello On 2005-03-20 sean finney wrote: > On Fri, Mar 18, 2005 at 04:33:52PM +0100, Martin Schulze wrote: > > sean finney wrote: > > > On Fri, Mar 11, 2005 at 09:39:10AM +0100, Christian Hammers wrote: > > > > Wasn't it the one where a privilege granted to "table_name" also > > > > grants rights on

Bug#296674: [CAN-2004-0957] i believe this patch should do it...

2005-03-18 Thread Martin Schulze
sean finney wrote: > On Fri, Mar 11, 2005 at 09:39:10AM +0100, Christian Hammers wrote: > > Wasn't it the one where a privilege granted to "table_name" also grants > > rights on "tableXname", "tableYname" as '_' was considered as something > > like a dot in a RegEx? This should be fairly easy to te

Bug#296674: [CAN-2004-0957] i believe this patch should do it...

2005-03-11 Thread sean finney
On Fri, Mar 11, 2005 at 09:39:10AM +0100, Christian Hammers wrote: > Wasn't it the one where a privilege granted to "table_name" also grants > rights on "tableXname", "tableYname" as '_' was considered as something > like a dot in a RegEx? This should be fairly easy to test. i knew it had somethin

Bug#296674: [CAN-2004-0957] i believe this patch should do it...

2005-03-11 Thread Christian Hammers
Hello Sean On 2005-03-11 sean finney wrote: > i believe the attached patch fixes the vulnerability. i took the redhat > src rpm patch "mysql-3.23.58-security.patch", removed the parts of the > patch that are already addressed by other DSA's, adjusted some line > numbers, and did a little extra ma

Bug#296674: [CAN-2004-0957] i believe this patch should do it...

2005-03-10 Thread sean finney
tags 285276 patch tags 296674 patch thanks hi, i believe the attached patch fixes the vulnerability. i took the redhat src rpm patch "mysql-3.23.58-security.patch", removed the parts of the patch that are already addressed by other DSA's, adjusted some line numbers, and did a little extra massag