oss-security February 2012 archive
Main Archive Page > Month Archives  > oss-security archives
oss-security: [oss-security] MySQL 0-day - does it need a CVE?

[oss-security] MySQL 0-day - does it need a CVE?

From: Kurt Seifried <kseifried_at_nospam>
Date: Thu Feb 09 2012 - 17:20:14 GMT
To: oss-security@lists.openwall.com, admin@vulndisco.net

https://lists.immunityinc.com/pipermail/canvas/2012-February/000011.html

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi,

We are releasing a working MySQL 5.5.20 remote 0day exploit with this
update.The exploit has been tested with mysql-5.5.20-debian6.0-i686.deb
on Debian 6.0.

Best,
Intevydis Ltd.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (Darwin)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iEYEARECAAYFAk8xdTEACgkQY8Flb3OI+Q2zXwCfQL5y+R8n+ipdMYIRdoVPkEdF
yeoAn26p3KmY0+WYFqKrb9/A3frNo2Xm
=m+1k
-----END PGP SIGNATURE-----

Does this need a CVE # or have you already gotten one from Mitre?

-- Kurt Seifried Red Hat Security Response Team (SRT)