MGASA-2020-0345 - Updated mysql-connector-python packages fix security vulnerability

Publication date: 25 Aug 2020
URL: https://advisories.mageia.org/MGASA-2020-0345.html
Type: security
Affected Mageia releases: 7
CVE: CVE-2019-2435

Easily exploitable vulnerability allows unauthenticated attacker with network
access via TLS to compromise MySQL Connectors. Successful attacks require human
interaction from a person other than the attacker. Successful attacks of this
vulnerability can result in unauthorized creation, deletion or modification
access to critical data or all MySQL Connectors accessible data as well as
unauthorized access to critical data or complete access to all MySQL Connectorsaccessible data (CVE-2019-2435).

Also, the protobuf package was updated to add a python3 subpackage, which was
needed for this update.

References:
- https://bugs.mageia.org/show_bug.cgi?id=26402
- https://www.oracle.com/security-alerts/cpujan2019.html
- - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-2435

SRPMS:
- 7/core/protobuf-3.6.1-1.1.mga7
- 7/core/mysql-connector-python-8.0.20-1.mga7

Mageia 2020-0345: mysql-connector-python security update

Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise MySQL Connectors

Summary

Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all MySQL Connectors accessible data as well as unauthorized access to critical data or complete access to all MySQL Connectorsaccessible data (CVE-2019-2435).
Also, the protobuf package was updated to add a python3 subpackage, which was needed for this update.

References

- https://bugs.mageia.org/show_bug.cgi?id=26402

- https://www.oracle.com/security-alerts/cpujan2019.html

- - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-2435

Resolution

MGASA-2020-0345 - Updated mysql-connector-python packages fix security vulnerability

SRPMS

- 7/core/protobuf-3.6.1-1.1.mga7

- 7/core/mysql-connector-python-8.0.20-1.mga7

Severity
Publication date: 25 Aug 2020
URL: https://advisories.mageia.org/MGASA-2020-0345.html
Type: security
CVE: CVE-2019-2435

Related News