[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] MySQL Install - Can't set root password



> No! Don't do that! 3.22.x has a big security hole. You need 3.22.30 or
> greater. (3.22.32 is the latest version.)

Can you tell me, what is the security hole? Thank you.


You really need to upgrade to the newest, 3.22.32, to be protected from the two vulnerabilities. More information on both are at the two urls on securityfocus:

MySQL GRANT Global Password Changing Vulnerability
http://www.securityfocus.com/vdb/bottom.html?vid=926

MySQL Unauthenticated Remote Access Vulnerability
http://www.securityfocus.com/vdb/bottom.html?vid=975


- Dave