[2901] in Privacy_Forum
[ PRIVACY Forum ] Serious new MySQL security vulnerability
daemon@ATHENA.MIT.EDU (PRIVACY Forum mailing list)
Tue Jun 12 02:00:01 2012
Date: Mon, 11 Jun 2012 22:44:26 -0700
To: privacy-list@vortex.com
Message-ID: <20120612054426.GB7635@vortex.com>
MIME-Version: 1.0
Content-Disposition: inline
From: PRIVACY Forum mailing list <privacy@vortex.com>
Reply-To: PRIVACY Forum mailing list <privacy@vortex.com>
Content-Type: text/plain; charset="iso-8859-1"
Errors-To: privacy-bounces+privacy-forum=mit.edu@vortex.com
Content-Transfer-Encoding: 8bit
Serious new MySQL security vulnerability
http://j.mp/LXunyu (Sucuri)
"A serious security vulnerability discovered in MySQL was disclosed
this weekend. It basically allows anyone to bypass authentication and
login directly into the database. We tried on a few 64bit Ubuntu
systems and were able to replicate the issue (it seems that only 64
bit platforms are affected)."
- - -
Of course, having MySQL accessible directly from the Net without
connection restrictions is A Bad Idea in any case.
--Lauren--
Lauren Weinstein (lauren@vortex.com): http://www.vortex.com/lauren
Co-Founder: People For Internet Responsibility: http://www.pfir.org
Founder:
- Data Wisdom Explorers League: http://www.dwel.org
- Network Neutrality Squad: http://www.nnsquad.org
- Global Coalition for Transparent Internet Performance: http://www.gctip.org
- PRIVACY Forum: http://www.vortex.com
Member: ACM Committee on Computers and Public Policy
Lauren's Blog: http://lauren.vortex.com
Google+: http://vortex.com/g+lauren / Twitter: http://vortex.com/t-lauren
Tel: +1 (818) 225-2800 / Skype: vortex.com
_______________________________________________
privacy mailing list
http://lists.vortex.com/mailman/listinfo/privacy