Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
This update for mariadb to version 10.2.15 fixes the following issues:
These security issues were fixed:
- CVE-2018-2767: Enforse use of SSL/TLS in embedded server library (Return
of BACKRONYM) (bsc#1088681).
- CVE-2018-2786: Vulnerability in the MySQL Server component of Oracle
MySQL (subcomponent: InnoDB). Easily exploitable vulnerability allowed
high privileged attacker with network access via multiple protocols to
compromise MySQL Server. Successful attacks of this vulnerability can
result in unauthorized ability to cause a hang or frequently repeatable
crash (complete DOS) of MySQL Server as well as unauthorized update,
insert or delete access to some of MySQL Server accessible data
(bsc#1089987).
- CVE-2018-2759: Vulnerability in the MySQL Server component of Oracle
MySQL (subcomponent: InnoDB). Easily exploitable vulnerability allowed
high privileged attacker with network access via multiple protocols to
...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.0:
zypper in -t patch openSUSE-2018-572=1
- openSUSE Leap 15.0 (i586 x86_64):
libmysqld-devel-10.2.15-lp150.2.3.2
libmysqld19-10.2.15-lp150.2.3.2
libmysqld19-debuginfo-10.2.15-lp150.2.3.2
mariadb-10.2.15-lp150.2.3.2
mariadb-bench-10.2.15-lp150.2.3.2
mariadb-bench-debuginfo-10.2.15-lp150.2.3.2
mariadb-client-10.2.15-lp150.2.3.2
mariadb-client-debuginfo-10.2.15-lp150.2.3.2
mariadb-debuginfo-10.2.15-lp150.2.3.2
mariadb-debugsource-10.2.15-lp150.2.3.2
mariadb-galera-10.2.15-lp150.2.3.2
mariadb-test-10.2.15-lp150.2.3.2
mariadb-test-debuginfo-10.2.15-lp150.2.3.2
mariadb-tools-10.2.15-lp150.2.3.2
mariadb-tools-debuginfo-10.2.15-lp150.2.3.2
- openSUSE Leap 15.0 (noarch):
mariadb-errormessages-10.2.15-lp150.2.3.2
https://www.suse.com/security/cve/CVE-2018-2755.html
https://www.suse.com/security/cve/CVE-2018-2759.html
https://www.suse.com/security/cve/CVE-2018-2761.html
https://www.suse.com/security/cve/CVE-2018-2766.html
https://www.suse.com/security/cve/CVE-2018-2767.html
https://www.suse.com/security/cve/CVE-2018-2771.html
https://www.suse.com/security/cve/CVE-2018-2777.html
https://www.suse.com/security/cve/CVE-2018-2781.html
https://www.suse.com/security/cve/CVE-2018-2782.html
https://www.suse.com/security/cve/CVE-2018-2784.html
https://https://www.suse.com/security/cve/CVE-2018-2786.html
https://www.suse.com/security/cve/CVE-2018-2787.html
https://www.suse.com/security/cve/CVE-2018-2810.html
https://www.suse.com/security/cve/CVE-2018-2813.html
https://www.suse.com/security/cve/CVE-2018-2817.html
https://www.suse.com/security/cve/CVE-2018-2819.html
https://bugzilla.suse.com/1088681
https://bugzilla.suse.com/1089987
https://bugzilla.suse.com/1090518
https://bugzilla.suse.com/1092544
--
Get the latest Linux and open source security news straight to your inbox.