全球主机交流论坛

标题: MySQL爆出大漏洞,只要知道用户名就可登录 [打印本页]

作者: lsylsy2    时间: 2012-6-11 11:17
标题: MySQL爆出大漏洞,只要知道用户名就可登录
本帖最后由 lsylsy2 于 2012-6-11 11:19 编辑

http://seclists.org/oss-sec/2012/q2/493

All MariaDB and MySQL versions up to 5.1.61, 5.2.11, 5.3.5, 5.5.22 are
vulnerable.
MariaDB versions from 5.1.62, 5.2.12, 5.3.6, 5.5.23 are not.
MySQL versions from 5.1.63, 5.5.24, 5.6.6 are not.

只要知道用户名【含root】,无需密码便可登录
迅速升级吧……

Update:不用那么担心,Linux下GCC默认MySQL基本没有漏洞

But practically it's better than it looks - many MySQL/MariaDB builds
are not affected by this bug.

Whether a particular build of MySQL or MariaDB is vulnerable, depends on
how and where it was built. A prerequisite is a memcmp() that can return
an arbitrary integer (outside of -128..127 range). To my knowledge gcc
builtin memcmp is safe, BSD libc memcmp is safe. Linux glibc
sse-optimized memcmp is not safe, but gcc usually uses the inlined
builtin version.

As far as I know, official vendor MySQL and MariaDB binaries are not
vulnerable.

References:

MariaDB bug report: https://mariadb.atlassian.net/browse/MDEV-212
MariaDB fix: http://bazaar.launchpad.net/~maria-captains/maria/5.1/revision/3144

MySQL bug report: http://bugs.mysql.com/bug.php?id=64884
MySQL fix: http://bazaar.launchpad.net/~mysql/mysql-server/5.1/revision/3560.10.17
MySQL changelog:
  http://dev.mysql.com/doc/refman/5.1/en/news-5-1-63.html
  http://dev.mysql.com/doc/refman/5.5/en/news-5-5-24.html

作者: uoin    时间: 2012-6-11 11:17
求利用工具。
作者: aite.me    时间: 2012-6-11 11:18
0day级别的,各位还是升级吧!
作者: domin    时间: 2012-6-11 11:19
Whether a particular build of MySQL or MariaDB is vulnerable, depends on
how and where it was built. A prerequisite is a memcmp() that can return
an arbitrary integer (outside of -128..127 range). To my knowledge gcc
builtin memcmp is safe, BSD libc memcmp is safe. Linux glibc
sse-optimized memcmp is not safe, but gcc usually uses the inlined
builtin version.

As far as I know, official vendor MySQL and MariaDB binaries are not
vulnerable.


作者: 云生    时间: 2012-6-11 11:20
这个好像要phpmyadmin 才能登录吧,
作者: 哆啦A梦    时间: 2012-6-11 11:21
官方一定有紧急升级的
作者: wybie    时间: 2012-6-11 11:25
不会这么严重吧...汗...
作者: smyz    时间: 2012-6-11 11:26
我擦,这么严重?
作者: David    时间: 2012-6-11 11:36
这么吓人
作者: skycms    时间: 2012-6-11 12:18
0day代码没找到
作者: Satoshi    时间: 2012-6-11 12:25
求真相
作者: iking    时间: 2012-6-11 12:26
同球啊。。。
作者: 360安全卫士    时间: 2012-6-11 12:27
云生 发表于 2012-6-11 11:20
这个好像要phpmyadmin 才能登录吧,

phpmyadmin只是个客户端,若SERVER无0DAY PHPMYADMIN只能做登录、验证密码的,他本身不包含密码
作者: dianso    时间: 2012-6-11 13:51
五年前就有了
作者: atrong    时间: 2012-6-11 14:48

这么吓人
作者: wdlth    时间: 2012-6-11 14:54
google perftools能利用不




欢迎光临 全球主机交流论坛 (https://sunk.eu.org/) Powered by Discuz! X3.4