tabris | 18 Aug 18:19

Bug#477072: mysql-server-5.0: Arbitrary data input plus GIS functions, causes mysql server crash

    This bug has been sitting around since July w/o a resolution.

    I tracked it down to a difference between i386 builds and AMD64. The
crash only occurs on AMD64. I think this is an important bug to be fixed
as it results in a minor reproducible DoS/data-loss (of temporary tables
and heap tables).

    At this point I am unclear on what to do about it, especially as I
contacted the maintainer directly 3 weeks ago and still have yet to
receive a response.

Norbert Tretkowski | 23 Aug 10:37

Bug#477072: mysql-server-5.0: Arbitrary data input plus GIS functions, causes mysql server crash

Am Montag, den 18.08.2008, 09:22 -0700 schrieb tabris:
> This bug has been sitting around since July w/o a resolution.
> 
>     I tracked it down to a difference between i386 builds and AMD64. The
> crash only occurs on AMD64. I think this is an important bug to be fixed
> as it results in a minor reproducible DoS/data-loss (of temporary tables
> and heap tables).
> 
>     At this point I am unclear on what to do about it, especially as I
> contacted the maintainer directly 3 weeks ago and still have yet to
> receive a response.

I am still unable to reproduce this crash, even on amd64. I get a bunch
of syntax errors when sourcing country.sql, but no crash when sourcing
mysql-crash.sql.

	Norbert

tabris | 23 Aug 20:04

Bug#477072: mysql-server-5.0: Arbitrary data input plus GIS functions, causes mysql server crash

Norbert Tretkowski wrote:
> Am Montag, den 18.08.2008, 09:22 -0700 schrieb tabris:
>    
>> This bug has been sitting around since July w/o a resolution.
>>
>>      I tracked it down to a difference between i386 builds and AMD64. The
>> crash only occurs on AMD64. I think this is an important bug to be fixed
>> as it results in a minor reproducible DoS/data-loss (of temporary tables
>> and heap tables).
>>
>>      At this point I am unclear on what to do about it, especially as I
>> contacted the maintainer directly 3 weeks ago and still have yet to
>> receive a response.
>>      
>
> I am still unable to reproduce this crash, even on amd64. I get a bunch
> of syntax errors when sourcing country.sql, but no crash when sourcing
> mysql-crash.sql.
>
> 	Norbert
>
>    
Find attached a clean copy of both files, and a tarball of them.

I'm guessing that the country.sql may have been corrupted somehow, thus 
the syntax errors.

Also, just updated to 5.0.51a-12, and it still happens.
(Continue reading)


Gmane