The foreign freeware mySQL is the problem. AND this has already been posted.
http://www.freerepublic.com/focus/f-chat/1330243/posts
This bug is less serious than Blaster was for MS-SQL, as its basically just a brute force attack on databases that allow root. This is like saying if someone allow external connections to a MSSQL database and I brute force their abc123 password its a problem with MSSQL..
I have to disagree with you again here. The worm inserts itself by using a brute-force method of using common passwords unti lone works. There is no vulnerability in the software itself--just the admins who administer it.
At least it's not as bad as the Slammer worm that took out so many MSSQL installations, an entire government got mad. BTW, it only works on Windows, while the "foreign freeware" Linux installation is immune.