FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2024-03-29 07:54:42 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date

k68

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
77420ebb-0cf4-11d9-8a8a-000c41e2cdadmysql -- heap buffer overflow with prepared statements

There is a buffer overflow in the prepared statements API (libmysqlclient) when a statement containing thousands of placeholders is executed.


Discovery 2004-09-08
Entry 2004-09-23
mysql-server
mysql-client
ge 4.1.0 le 4.1.4

http://bugs.mysql.com/bug.php?id=5194
http://dev.mysql.com/doc/mysql/en/News-4.1.5.html
http://mysql.bkbits.net:8080/mysql-4.1/cset@1.1932.152.4
2e129846-8fbb-11d8-8b29-0020ed76ef5aMySQL insecure temporary file creation (mysqlbug)

Shaun Colley reports that the script `mysqlbug' included with MySQL sometimes creates temporary files in an unsafe manner. As a result, an attacker may create a symlink in /tmp so that if another user invokes `mysqlbug' and quits without making any changes, an arbitrary file may be overwritten with the bug report template.


Discovery 2004-03-25
Entry 2004-04-16
Modified 2004-05-21
mysql-client
ge 4.0 lt 4.0.20

ge 4.1 lt 4.1.1_2

ge 5.0 lt 5.0.0_2

http://marc.theaimsgroup.com/?l=bugtraq&m=108023246916294&w=2
http://bugs.mysql.com/bug.php?id=3284
9976
CVE-2004-0381