Advertisement
eromang

More than 1 year to patch YaSSL vulnerabilities in MySQL

Jul 19th, 2012
290
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.58 KB | None | 0 0
  1. yaSSL Release notes, version 1.5.8 (1/10/07) in mysql-5.5.21 released the 2012-01-31
  2. yaSSL Release notes, version 2.1.2 (9/2/2011) in mysql-5.5.22 released the 2012-03-03
  3.  
  4. But yaSSL version 2.0.0 (7/6/2010) has correct vulnerabilities SA38344 and SA37493 present in version 1.9.9.
  5. SA38344 was released the 2010-01-27 and SA37493 the 2010-01-28. Impacts DoS from remote.
  6.  
  7. So Oracle MySQL Server has patch 1 year and three months after the release of the vulnerabilities.
  8.  
  9. No mentions in Oracle April 2012 CPU
  10. http://www.oracle.com/technetwork/topics/security/cpuapr2012verbose-366316.html
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement