First published: Tue Nov 30 2010(Updated: )
mysql-gui-tools (mysql-query-browser and mysql-admin) before 5.0r14+openSUSE-2.3 exposes the password of a user connected to the MySQL server in clear text form via the list of running processes.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/mysql-gui-tools | ||
MySQL GUI Tools | <5.0r14\+opensuse-2.3 | |
Fedora | =12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-4177 has a medium severity rating due to the exposure of user passwords in clear text.
To fix CVE-2010-4177, update to version 5.0r14+openSUSE-2.3 or later.
CVE-2010-4177 affects mysql-gui-tools including mysql-query-browser and mysql-admin before version 5.0r14+openSUSE-2.3.
The impact of CVE-2010-4177 is the unauthorized disclosure of MySQL user passwords to other users on the system.
If you cannot update to a patched version for CVE-2010-4177, consider restricting access to the system and processes to trusted users only.