mysql: A true Multi-User, Multi-Threaded SQL Database Server ---------------------------------------------------------------------- File: mysql-4.0.18-32.23.i586.rpm Patchrpm: mysql-4.0.18-32.23.i586.patch.rpm Version: 4.0.18-32.23 Size: 7417 kB Patchsize: 2151 kB Date: Tue 09 May 2006 2:17:56 CEST Source: mysql-4.0.18-32.23.src.rpm Security: Yes ---------------------------------------------------------------------- Description: Attackers could read portions of memory by using a user name with trailing null byte or via COM_TABLE_DUMP command (CVE-2006-1516, CVE-2006-1517). Attackers could execute arbitrary code by causing a buffer overflow via specially crafted COM_TABLE_DUMP packets (CVE-2006-1518).