Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

openSUSE: Security Update 2020:0409-1 for python-mysql-connector-python

opensuse
Calendar Grey March 29, 2020
Dist Opensuse Esm H88
This patch addresses a notable vulnerability in the python-mysql-connector-python package for openSUSE, reinforcing the security of the system.
An update that fixes one vulnerability is now available.

Description

This update for python-mysql-connector-python fixes the following issues:

python-mysql-connector-python was updated to 8.0.19 (boo#1122204 -

CVE-2019-2435):

- WL#13531: Remove xplugin namespace

- WL#13372: DNS SRV support

- WL#12738: Specify TLS ciphers to be used by a client or session

- BUG#30270760: Fix reserved filed should have a length of 22

- BUG#29417117: Close file in handle load data infile

- WL#13330: Single C/Python (Win) MSI installer

- WL#13335: Connectors should handle expired password sandbox without SET

operations

- WL#13194: Add support for Python 3.8

- BUG#29909157: Table scans of floats causes memory leak with the C

extension

- BUG#25349794: Add read_default_file alias for option_files in connect()

- WL#13155: Support new utf8mb4 bin collation

- WL#12737: Add overlaps and not_overlaps as operator

- WL#12735: Add README.rst and CONTRIBUTING.rst files

- WL#12227: Indexing array fields

- WL#12085:...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.1:

zypper in -t patch openSUSE-2020-409=1

Package List

- openSUSE Leap 15.1 (noarch):

python2-mysql-connector-python-8.0.19-lp151.3.3.1

python3-mysql-connector-python-8.0.19-lp151.3.3.1

References

https://www.suse.com/security/cve/CVE-2019-2435.html

https://bugzilla.suse.com/1122204

--

Announcement ID: openSUSE-SU-2020:0409-1
Rating: moderate
Affected Products: openSUSE Leap 15.1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here