DSA-1877-1

NameDSA-1877-1
SourceDebian
Descriptionmysql-dfsg-5.0 - arbitrary code
ReferencesCVE-2009-2446
Debian/oldstablepackage mysql-dfsg-5.0 is fixed in oldstable-security.
Debian/stablenot vulnerable
Debian/testingnot known to be vulnerable
Debian/unstablenot known to be vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
mysql-dfsg-5.0 (PTS)etch5.0.32-7etch8vulnerable
etch (security)5.0.32-7etch11fixed
lenny (security)5.0.51a-24+lenny2fixed
lenny5.0.51a-24+lenny2+spu1fixed

The next table lists affected binary packages.

Binary PackageReleaseVersionStatusArchitecures
libmysqlclient15-dev, libmysqlclient15off, mysql-client-5.0, mysql-server-4.1, mysql-server-5.0etch5.0.32-7etch8vulnerablealpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390, sparc
etch (security)5.0.32-7etch10vulnerables390
etch (security)5.0.32-7etch11fixedalpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, sparc
libmysqlclient15-dev, libmysqlclient15off, mysql-client-5.0, mysql-server-5.0lenny (security)5.0.51a-24+lenny2fixedalpha, amd64, arm, armel, hppa, i386, ia64, mips, mipsel, powerpc, s390, sparc
lenny5.0.51a-24+lenny2+spu1fixedalpha, amd64, arm, armel, hppa, i386, ia64, mips, mipsel, powerpc, s390, sparc
mysql-client, mysql-common, mysql-serveretch5.0.32-7etch8vulnerableall
etch (security)5.0.32-7etch11fixedall
lenny (security)5.0.51a-24+lenny2fixedall
lenny5.0.51a-24+lenny2+spu1fixedall

The information above is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
mysql-dfsg-5.0sourceetch5.0.32-7etch11unknown
mysql-dfsg-5.0sourcelenny5.0.51a-24+lenny2unknown

Search for package or bug name: Reporting problems

Home - Testing Security Team - Debian Security - Imprint