Re: Zero Day MySQL Buffer Overflow

2012-12-06 Thread daniel curtis
Hi Thijs! Okay now everything is clear. Regards!

Re: Zero Day MySQL Buffer Overflow

2012-12-04 Thread Thijs Kinkhorst
Hi Daniel, On Tue, December 4, 2012 18:33, daniel curtis wrote: > Thank You, I should look there first (Security Tracker). But I see, > that two of three CVE's are marked as 'vulnerable' for all branches; > stable, testing and unstable. Frankly, only first CVE is Fixed for > Squeeze. > It is norm

Re: Zero Day MySQL Buffer Overflow

2012-12-04 Thread daniel curtis
Hi, Thank You, I should look there first (Security Tracker). But I see, that two of three CVE's are marked as 'vulnerable' for all branches; stable, testing and unstable. Frankly, only first CVE is Fixed for Squeeze. It is normal? Regards!

Re: Zero Day MySQL Buffer Overflow

2012-12-03 Thread Carlos Alberto Lopez Perez
On 02/12/12 22:50, daniel curtis wrote: > Hi, > > I would like to inform about a new stack-based buffer overflow > vulnerability for MySQL. The following CVEs have been assigned > to track this MySQL vulnerability: > > CVE-2012-5611 MySQL (Linux) Stack based buffer overrun PoC Zeroday > CVE-2012-

Zero Day MySQL Buffer Overflow

2012-12-02 Thread daniel curtis
Hi, I would like to inform about a new stack-based buffer overflow vulnerability for MySQL. The following CVEs have been assigned to track this MySQL vulnerability: CVE-2012-5611 MySQL (Linux) Stack based buffer overrun PoC Zeroday CVE-2012-5612 MySQL (Linux) Heap Based Overrun PoC Zeroday CVE-20