RHSA-2011:0164: Moderate: mysql security update

Published Jan 18, 2011
·
Updated

MySQL is a multi-user, multi-threaded SQL database server. It consists ofthe MySQL server daemon (mysqld) and many client programs and libraries.The MySQL PolyFromWKB() function did not sanity check Well-Known Binary(WKB) data, which could allow a remote, authenticated attacker to crashmysqld. (CVE-2010-3840)A flaw in the way MySQL processed certain JOIN queries could allow aremote, authenticated attacker to cause excessive CPU use (up to 100%), ifa stored procedure contained JOIN queries, and that procedure was executedtwice in sequence. (CVE-2010-3839)A flaw in the way MySQL processed queries that provide a mixture of numericand longblob data types to the LEAST or GREATEST function, could allow aremote, authenticated attacker to crash mysqld. (CVE-2010-3838)A flaw in the way MySQL processed PREPARE statements containing bothGROUPCONCAT and the WITH ROLLUP modifier could allow a remote,authenticated attacker to crash mysqld. (CVE-2010-3837)MySQL did not properly pre-evaluate LIKE arguments in view prepare mode,possibly allowing a remote, authenticated attacker to crash mysqld.(CVE-2010-3836)A flaw in the way MySQL processed statements that assign a value to auser-defined variable and that also contain a logical value evaluationcould allow a remote, authenticated attacker to crash mysqld.(CVE-2010-3835)A flaw in the way MySQL evaluated the arguments of extreme-value functions,such as LEAST and GREATEST, could allow a remote, authenticated attacker tocrash mysqld. (CVE-2010-3833)A flaw in the way MySQL handled LOAD DATA INFILE requests allowed MySQL tosend OK packets even when there were errors. (CVE-2010-3683)A flaw in the way MySQL processed EXPLAIN statements for some complexSELECT queries could allow a remote, authenticated attacker to crashmysqld. (CVE-2010-3682)A flaw in the way MySQL processed certain alternating READ requestsprovided by HANDLER statements could allow a remote, authenticated attackerto crash mysqld. (CVE-2010-3681)A flaw in the way MySQL processed CREATE TEMPORARY TABLE statements thatdefine NULL columns when using the InnoDB storage engine, could allow aremote, authenticated attacker to crash mysqld. (CVE-2010-3680)A flaw in the way MySQL processed certain values provided to the BINLOGstatement caused MySQL to read unassigned memory. A remote, authenticatedattacker could possibly use this flaw to crash mysqld. (CVE-2010-3679)A flaw in the way MySQL processed SQL queries containing IN or CASEstatements, when a NULL argument was provided as one of the arguments tothe query, could allow a remote, authenticated attacker to crash mysqld.(CVE-2010-3678)A flaw in the way MySQL processed JOIN queries that attempt to retrievedata from a unique SET column could allow a remote, authenticated attackerto crash mysqld. (CVE-2010-3677)Note: CVE-2010-3840, CVE-2010-3838, CVE-2010-3837, CVE-2010-3835,CVE-2010-3833, CVE-2010-3682, CVE-2010-3681, CVE-2010-3680, CVE-2010-3678,and CVE-2010-3677 only cause a temporary denial of service, as mysqld wasautomatically restarted after each crash.These updated packages upgrade MySQL to version 5.1.52. Refer to the MySQLrelease notes for a full list of changes:http://dev.mysql.com/doc/refman/5.1/en/news-5-1-52.html All MySQL users should upgrade to these updated packages, which correctthese issues. After installing this update, the MySQL server daemon(mysqld) will be restarted automatically.

Affected Software

18 affected componentsFixes available
redhat/mysql<5.1.52-1.el6_0.1
5.1.52-1.el6_0.1
redhat/mysql<5.1.52-1.el6_0.1
5.1.52-1.el6_0.1
redhat/mysql-bench<5.1.52-1.el6_0.1
5.1.52-1.el6_0.1
redhat/mysql-debuginfo<5.1.52-1.el6_0.1
5.1.52-1.el6_0.1
redhat/mysql-debuginfo<5.1.52-1.el6_0.1
5.1.52-1.el6_0.1
redhat/mysql-devel<5.1.52-1.el6_0.1
5.1.52-1.el6_0.1
redhat/mysql-devel<5.1.52-1.el6_0.1
5.1.52-1.el6_0.1
redhat/mysql-embedded<5.1.52-1.el6_0.1
5.1.52-1.el6_0.1
redhat/mysql-embedded<5.1.52-1.el6_0.1
5.1.52-1.el6_0.1
redhat/mysql-embedded-devel<5.1.52-1.el6_0.1
5.1.52-1.el6_0.1
redhat/mysql-embedded-devel<5.1.52-1.el6_0.1
5.1.52-1.el6_0.1
redhat/mysql-libs<5.1.52-1.el6_0.1
5.1.52-1.el6_0.1
redhat/mysql-libs<5.1.52-1.el6_0.1
5.1.52-1.el6_0.1
redhat/mysql-server<5.1.52-1.el6_0.1
5.1.52-1.el6_0.1
redhat/mysql-test<5.1.52-1.el6_0.1
5.1.52-1.el6_0.1
redhat/mysql-bench<5.1.52-1.el6_0.1
5.1.52-1.el6_0.1
redhat/mysql-server<5.1.52-1.el6_0.1
5.1.52-1.el6_0.1
redhat/mysql-test<5.1.52-1.el6_0.1
5.1.52-1.el6_0.1

Remediation

Event History

Jan 18, 2011
Advisory Published
12:00 AM

Frequently Asked Questions

1

What is the severity of RHSA-2011:0164?

The severity of RHSA-2011:0164 is classified as moderate.

2

How do I fix RHSA-2011:0164?

You can fix RHSA-2011:0164 by updating MySQL to version 5.1.52-1.el6_0.1 or later.

3

What software is affected by RHSA-2011:0164?

RHSA-2011:0164 affects various MySQL packages including mysql, mysql-server, and mysql-devel.

4

Is RHSA-2011:0164 an exploitable vulnerability?

Yes, RHSA-2011:0164 can be exploited due to insufficient sanity checks in the MySQL PolyFromWKB() function.

5

Do I need to restart MySQL after applying the fix for RHSA-2011:0164?

Yes, a restart of MySQL is recommended after applying the fix for RHSA-2011:0164 to ensure the changes take effect.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203