Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Mageia: 2020-0345 Critical: MySQL Connector Security Update CVE-2019-2435

mageia
Calendar Grey August 25, 2020
Dist Mageia Esm H88
Important security patch for mysql-connector-python resolves CVE-2019-2435 flaws that permit unauthorized entry.
Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise MySQL Connectors

Summary

Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all MySQL Connectors accessible data as well as unauthorized access to critical data or complete access to all MySQL Connectorsaccessible data (CVE-2019-2435).
Also, the protobuf package was updated to add a python3 subpackage, which was needed for this update.

References

- https://bugs.mageia.org/show_bug.cgi?id=26402

- https://www.oracle.com/security-alerts/cpujan2019.html

- - https://www.cve.org/CVERecord?id=CVE-2019-2435

Resolution

SRPMS

- 7/core/protobuf-3.6.1-1.1.mga7

- 7/core/mysql-connector-python-8.0.20-1.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 25 Aug 2020
URL: https://advisories.mageia.org/MGASA-2020-0345.html
Type: security
CVE: CVE-2019-2435

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here