back to article All ready for that Easter holiday? Here's a mild MySQL security bug

A programming blunder has been uncovered in Oracle's MySQL that can potentially leak usernames and passwords to man-in-the-middle eavesdroppers. Known as "The Riddle," the flaw potentially allows a miscreant to intercept and obtain login credentials sent from MySQL clients 5.5 and 5.6 to servers. Apparently, a fix introduced …

  1. a_yank_lurker

    Leisure Larry's Minions

    Nothing new, fixing the issue leaves less money for Leisure Larry and his minions for their yachts.

    1. Anonymous Coward
      Trollface

      Re: Leisure Larry's Minions

      Wasn't the whole idea of open source you give away the code and then make money selling support? Oracle is taking that literally!

  2. Anonymous C0ward

    Does anyone with a clue expose their MySQL port to the world?

    1. Anonymous Coward
      Anonymous Coward

      Still, you may have attackers already inside your network, and vulnerabilities like this allows to expand the attack and gather useful data. Then there are bad configured systems....

  3. John Latham

    Upgrade to 5.7?

    Probably want to read about default_password_lifetime when you do it.

  4. Potemkine Silver badge

    Name change

    Instead of Oracle, I suggest "Debacle", it would be less deceptive.

  5. Anonymous Coward
    Anonymous Coward

    The quote in this article improperly implies that being an Oracle customer makes security reports useful. As a former Oracle customer, I can attest that it does not. And that's precisely the reason of the "former".

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like