Bug#784982: [debian-mysql] Bug#784982: mysql-server: False positive when checking for insecure root accounts

2015-05-11 Thread Otto Kekäläinen
Related to this issue: The MariaDB 10.0 in Debian unstable uses auth_socket for root account by default now and has already that line removed. The MariaDB 10.0 version in Jessie is however affected. -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubs

Bug#784982: mysql-server: False positive when checking for insecure root accounts

2015-05-11 Thread Guilhem Moulin
Package: mysql-server Version: 5.5.42-1 Severity: normal Dear Maintainer, When checking for insecure root accounts, ‘debian-start.inc.sh’ merely lists root accounts with an empty password: SELECT COUNT(*) FROM mysql.user WHERE user='root' and password=''; However, such an account can be per