
{"id":953,"date":"2010-07-22T15:13:21","date_gmt":"2010-07-22T14:13:21","guid":{"rendered":"http:\/\/dasini.net\/blog\/?p=953"},"modified":"2010-07-22T15:13:21","modified_gmt":"2010-07-22T14:13:21","slug":"vulnerabilites-mysql-5-1-47","status":"publish","type":"post","link":"https:\/\/dasini.net\/blog\/2010\/07\/22\/vulnerabilites-mysql-5-1-47\/","title":{"rendered":"Vuln\u00e9rabilit\u00e9s MySQL 5.1.47"},"content":{"rendered":"<p>Les versions ant\u00e9rieurs \u00e0 5.1.47 MySQL souffrent de vuln\u00e9rabilit\u00e9s:<\/p>\n<ul>\n<li>d\u00e9ni de service. Cet effet peut se produire lorsque le serveur de base de donn\u00e9es re\u00e7oit un paquet dont la taille est sup\u00e9rieure \u00e0 la taille maximale autoris\u00e9e.<\/li>\n<li>d\u00e9bordement de m\u00e9moire (buffer overflow). Cet effet se produit lorsque l\u2019argument pass\u00e9 \u00e0 la commande \u00ab\u00a0COM_FILED_LIST\u00a0\u00bb est tr\u00e8s long. L\u2019utilisateur doit cependant \u00eatre authentifi\u00e9 pour exploiter cette vuln\u00e9rabilit\u00e9.<\/li>\n<\/ul>\n<p><span style=\"text-decoration: underline;\">Versions affect\u00e9es<\/span>:\u00a0 Versions ant\u00e9rieures \u00e0 5.1.47<\/p>\n<p><span style=\"text-decoration: underline;\">Criticit\u00e9<\/span>: Moyenne<\/p>\n<p><span style=\"text-decoration: underline;\">Solution<\/span>: Mises \u00e0 jour disponibles sur les diff\u00e9rentes distributions<\/p>\n<div id=\"_mcePaste\" style=\"position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow: hidden;\">\n<p>MySQL souffre d\u2019une vuln\u00e9rabilit\u00e9 de d\u00e9ni de service. Cet effet peut se produire lorsque<\/p>\n<p>le serveur de base de donn\u00e9es re\u00e7oit un paquet dont la taille est sup\u00e9rieure \u00e0 la taille<\/p>\n<p>maximale autoris\u00e9e.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Les versions ant\u00e9rieurs \u00e0 5.1.47 MySQL souffrent de vuln\u00e9rabilit\u00e9s:<\/p>\n<p>    * d\u00e9ni de service. Cet effet peut se produire lorsque le serveur de base de donn\u00e9es re\u00e7oit un paquet dont la taille est sup\u00e9rieure \u00e0 la taille maximale autoris\u00e9e.<br \/>\n    * d\u00e9bordement de m\u00e9moire (buffer overflow). Cet effet se produit lorsque l\u2019argument pass\u00e9 \u00e0 la commande \u00ab\u00a0COM_FILED_LIST\u00a0\u00bb est tr\u00e8s long. L\u2019utilisateur doit cependant \u00eatre authentifi\u00e9 pour exploiter cette vuln\u00e9rabilit\u00e9.<br \/>\n    *<\/p>\n<p>Versions affect\u00e9es:  Versions ant\u00e9rieures \u00e0 5.1.47<\/p>\n<p>Criticit\u00e9: Moyenne<\/p>\n<p>Solution: Mises \u00e0 jour disponibles sur les diff\u00e9rentes distributions<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"footnotes":""},"categories":[8],"tags":[],"class_list":["post-953","post","type-post","status-publish","format-standard","hentry","category-mysql"],"aioseo_notices":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p9LfWW-fn","jetpack-related-posts":[{"id":912,"url":"https:\/\/dasini.net\/blog\/2010\/05\/28\/audit-mysql-tmp_table_size-max_heap_table_size\/","url_meta":{"origin":953,"position":0},"title":"Audit MySQL &#8211; tmp_table_size &#038; max_heap_table_size","author":"Olivier DASINI","date":"28 mai 2010","format":false,"excerpt":"Je suis amen\u00e9 \u00e0 r\u00e9aliser r\u00e9guli\u00e8rement des audits de serveurs MySQL.Voici le premier volet d'une s\u00e9rie d'articles o\u00f9 je vais essayer de vous donner quelques points cl\u00e9s pour mieux comprendre le fonctionnement de MySQL. La configuration du serveur est un des points que je regarde, et l'une des erreurs les\u2026","rel":"","context":"Dans &quot;Astuce&quot;","block_context":{"text":"Astuce","link":"https:\/\/dasini.net\/blog\/category\/astuce\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":41,"url":"https:\/\/dasini.net\/blog\/2008\/10\/30\/mysql-50-un-sgbdr-mature-part-44\/","url_meta":{"origin":953,"position":1},"title":"MySQL 5.0 : Un SGBDR mature ? &#8212; (part 4\/4)","author":"Olivier DASINI","date":"30 octobre 2008","format":false,"excerpt":"Les d\u00e9clencheurs (triggers) sont des ordres de d\u00e9clenchement d'op\u00e9rations quand un \u00e9v\u00e8nement survient sur une table.","rel":"","context":"Dans &quot;MySQL&quot;","block_context":{"text":"MySQL","link":"https:\/\/dasini.net\/blog\/category\/mysql\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":1795,"url":"https:\/\/dasini.net\/blog\/2017\/07\/24\/ou-telecharger-mysql\/","url_meta":{"origin":953,"position":2},"title":"O\u00f9 t\u00e9l\u00e9charger MySQL ?","author":"Olivier DASINI","date":"24 juillet 2017","format":false,"excerpt":"Lorsque l'on d\u00e9marre un nouveau projet, il est en g\u00e9n\u00e9ral conseill\u00e9 de partir sur la version la plus r\u00e9cente de MySQL, histoire de profiter des toutes derni\u00e8res fonctionnalit\u00e9s mais aussi (surtout ?) d'\u00eatre certain d'\u00eatre \u00e0 jour au niveau des patchs de s\u00e9curit\u00e9. Cet article centralise les diff\u00e9rentes URLs pour\u2026","rel":"","context":"Dans &quot;Astuce&quot;","block_context":{"text":"Astuce","link":"https:\/\/dasini.net\/blog\/category\/astuce\/"},"img":{"alt_text":"Powered by MySQL","src":"https:\/\/i0.wp.com\/dasini.net\/blog\/wp-content\/uploads\/powered-by-mysql-125x64.png?resize=350%2C200","width":350,"height":200},"classes":[]},{"id":595,"url":"https:\/\/dasini.net\/blog\/2009\/04\/20\/le-programmateur-devenements-event-scheduler-part-16-2\/","url_meta":{"origin":953,"position":3},"title":"Le programmateur d&rsquo;\u00e9v\u00e9nements ( Event Scheduler ) (part 1\/6)","author":"Olivier DASINI","date":"20 avril 2009","format":false,"excerpt":"Poursuivons l'exploration des fonctionnalit\u00e9s phares de MySQL 5.1, et penchons-nous sur le programmateur d'\u00e9v\u00e8nements (Event Scheduler) pr\u00e9sent depuis MySQL 5.1.6 . Cet article est r\u00e9dig\u00e9 avec la version 5.1.22 de MySQL. Qu'est-ce qu'un programmateur d'\u00e9v\u00e8nements ? Le programmateur d'\u00e9v\u00e9nements ou \u00ab event scheduler \u00bb offre la possibilit\u00e9, \u00e0 l'administrateur de\u2026","rel":"","context":"Dans &quot;MySQL&quot;","block_context":{"text":"MySQL","link":"https:\/\/dasini.net\/blog\/category\/mysql\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":1082,"url":"https:\/\/dasini.net\/blog\/2011\/07\/19\/suffix-log-dans-la-version-du-serveur\/","url_meta":{"origin":953,"position":4},"title":"Suffix -log dans la version du serveur","author":"Olivier DASINI","date":"19 juillet 2011","format":false,"excerpt":"La r\u00e9ponse \u00e0 une question existentielle qui m'a occup\u00e9e une petite heure... Que repr\u00e9sente la suffix de certaines versions du MySQL ? Un exemple pour \u00eatre plus clair:","rel":"","context":"Dans &quot;Divers&quot;","block_context":{"text":"Divers","link":"https:\/\/dasini.net\/blog\/category\/divers\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":1227,"url":"https:\/\/dasini.net\/blog\/2012\/03\/30\/mysql-5-6-rocks\/","url_meta":{"origin":953,"position":5},"title":"MySQL 5.6 rock !","author":"Olivier DASINI","date":"30 mars 2012","format":false,"excerpt":"Comme d'habitude, mon but n'est pas de conna\u00eetre les possibilit\u00e9s maximales du serveur (d'autres le font mieux que moi), mais plut\u00f4t d'avoir une id\u00e9e assez pr\u00e9cise de leurs comportements respectifs dans un environnement le plus proche possible de ma prod. pour ce test, les candidats sont, Percona 5.5, MariaDB 5.3\u2026","rel":"","context":"Dans &quot;bench&quot;","block_context":{"text":"bench","link":"https:\/\/dasini.net\/blog\/category\/bench\/"},"img":{"alt_text":"dasini.net - 95 centile","src":"https:\/\/i0.wp.com\/dasini.net\/blog\/wp-includes\/images\/percentil.png?resize=350%2C200","width":350,"height":200},"classes":[]}],"jetpack_likes_enabled":true,"_links":{"self":[{"href":"https:\/\/dasini.net\/blog\/wp-json\/wp\/v2\/posts\/953","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dasini.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dasini.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dasini.net\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/dasini.net\/blog\/wp-json\/wp\/v2\/comments?post=953"}],"version-history":[{"count":2,"href":"https:\/\/dasini.net\/blog\/wp-json\/wp\/v2\/posts\/953\/revisions"}],"predecessor-version":[{"id":955,"href":"https:\/\/dasini.net\/blog\/wp-json\/wp\/v2\/posts\/953\/revisions\/955"}],"wp:attachment":[{"href":"https:\/\/dasini.net\/blog\/wp-json\/wp\/v2\/media?parent=953"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dasini.net\/blog\/wp-json\/wp\/v2\/categories?post=953"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dasini.net\/blog\/wp-json\/wp\/v2\/tags?post=953"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}