Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

RedHat RHSA-2020:3518-01 Important: rh-mysql80-mysql Security Update

red hat
Calendar Grey August 19, 2020
Dist Redhat Esm H88
Crucial security patch for rh-mysql80-mysql on Red Hat. Examine the modifications and resolutions addressing vulnerabilities.
An update for rh-mysql80-mysql is now available for Red Hat Software Collections

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

After installing this update, the MySQL server daemon (mysqld) will be restarted automatically.

Summary

MySQL is a multi-user, multi-threaded SQL database server. It consists of the MySQL server daemon, mysqld, and many client programs.
The following packages have been upgraded to a later upstream version: rh-mysql80-mysql (8.0.21).
Security Fix(es):
* mysql: Server: Security: Privileges multiple unspecified vulnerabilities (CVE-2020-14663, CVE-2020-14678, CVE-2020-14697, CVE-2020-2761, CVE-2020-2774, CVE-2020-2779, CVE-2020-2853, CVE-2020-14586, CVE-2020-14702)
* mysql: Server: Security: Encryption multiple unspecified vulnerabilities (CVE-2019-2914, CVE-2019-2957)
* mysql: InnoDB multiple unspecified vulnerabilities (CVE-2019-2938, CVE-2019-2963, CVE-2019-2968, CVE-2019-3018, CVE-2020-2577, CVE-2020-2589, CVE-2020-2760, CVE-2020-2762, CVE-2020-2814, CVE-2020-2893, CVE-2020-2895, CVE-2020-14568, CVE-2020-14623, CVE-2020-14633, CVE-2020-14634)
* mysql: Server: PS multiple unspecified vulnerabilities (CVE-2019-2946, CVE-2020-2925)
* mysql: Server: Replication multiple unspecified vulnerabilities (CVE-2019-2960, CVE-2020-2759, CVE-2020-2763, CVE-2020-14567)
* mysql: Server: Optimizer multiple unspecified vulnerabilities (CVE-2019-2966, CVE-2019-2967, CVE-2019-2974, CVE-2019-2982, CVE-2019-2991, CVE-2019-2998, CVE-2020-2579, CVE-2020-2660, CVE-2020-2679, CVE-2020-2686, CVE-2020-2765, CVE-2020-2892, CVE-2020-2897, CVE-2020-2901, CVE-2020-2904, CVE-2020-2923, CVE-2020-2924, CVE-2020-2928, CVE-2020-14539, CVE-2020-14547, CVE-2020-14597, CVE-2020-14614, CVE-2020-14654, CVE-2020-14680, CVE-2020-14725)
* mysql: Server: C API multiple unspecified vulnerabilities (CVE-2019-2993, CVE-2019-3011)
* mysql: Server: DDL multiple unspecified vulnerabilities (CVE-2019-2997, CVE-2020-2580)
* mysql: Server: Parser multiple unspecified vulnerabilities (CVE-2019-3004, CVE-2020-2627, CVE-2020-2930, CVE-2020-14619)
* mysql: Server: Connection unspecified vulnerability (CVE-2019-3009)
* mysql: Server: Options multiple unspecified vulnerabilities (CVE-2020-2584, CVE-2020-14632)
* mysql: Server: DML multiple unspecified vulnerabilities (CVE-2020-2588, CVE-2020-2780, CVE-2020-14540, CVE-2020-14575, CVE-2020-14620)
* mysql: C API multiple unspecified vulnerabilities (CVE-2020-2752, CVE-2020-2922, CVE-2020-14550, CVE-2020-2570, CVE-2020-2573, CVE-2020-2574)
* mysql: Server: Logging unspecified vulnerability (CVE-2020-2770)
* mysql: Server: Memcached unspecified vulnerability (CVE-2020-2804)
* mysql: Server: Stored Procedure unspecified vulnerability (CVE-2020-2812)
* mysql: Server: Information Schema multiple unspecified vulnerabilities (CVE-2020-2896, CVE-2020-14559, CVE-2020-2694)
* mysql: Server: Charsets unspecified vulnerability (CVE-2020-2898)
* mysql: Server: Connection Handling unspecified vulnerability (CVE-2020-2903)
* mysql: Server: Group Replication Plugin unspecified vulnerability (CVE-2020-2921)
* mysql: Server: Group Replication GCS unspecified vulnerability (CVE-2020-2926)
* mysql: Server: Pluggable Auth unspecified vulnerability (CVE-2020-14553)
* mysql: Server: UDF unspecified vulnerability (CVE-2020-14576)
* mysql: Server: JSON unspecified vulnerability (CVE-2020-14624)
* mysql: Server: Security: Audit unspecified vulnerability (CVE-2020-14631)
* mysql: Server: Security: Roles multiple unspecified vulnerabilities (CVE-2020-14641, CVE-2020-14643, CVE-2020-14651)
* mysql: Server: Locking unspecified vulnerability (CVE-2020-14656)
* mysql: Information Schema unspecified vulnerability (CVE-2019-2911)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References

https://access.redhat.com/security/cve/CVE-2019-2911 https://access.redhat.com/security/cve/CVE-2019-2914 https://access.redhat.com/security/cve/CVE-2019-2938 https://access.redhat.com/security/cve/CVE-2019-2946 https://access.redhat.com/security/cve/CVE-2019-2957 https://access.redhat.com/security/cve/CVE-2019-2960 https://access.redhat.com/security/cve/CVE-2019-2963 https://access.redhat.com/security/cve/CVE-2019-2966 https://access.redhat.com/security/cve/CVE-2019-2967 https://access.redhat.com/security/cve/CVE-2019-2968 https://access.redhat.com/security/cve/CVE-2019-2974 https://access.redhat.com/security/cve/CVE-2019-2982 https://access.redhat.com/security/cve/CVE-2019-2991 https://access.redhat.com/security/cve/CVE-2019-2993 https://access.redhat.com/security/cve/CVE-2019-2997 https://access.redhat.com/security/cve/CVE-2019-2998 https://access.redhat.com/security/cve/CVE-2019-3004 https://access.redhat.com/security/cve/CVE-2019-3009 https://access.redhat.com/security/cve/CVE-2019-3011 https://access.redhat.com/security/cve/CVE-2019-3018 https://access.redhat.com/security/cve/CVE-2020-2570 https://access.redhat.com/security/cve/CVE-2020-2573 https://access.redhat.com/security/cve/CVE-2020-2574 https://access.redhat.com/security/cve/CVE-2020-2577 Read the Full Advisory

Package List

Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7):
Source: rh-mysql80-mysql-8.0.21-1.el7.src.rpm
aarch64: rh-mysql80-mysql-8.0.21-1.el7.aarch64.rpm rh-mysql80-mysql-common-8.0.21-1.el7.aarch64.rpm rh-mysql80-mysql-config-8.0.21-1.el7.aarch64.rpm rh-mysql80-mysql-config-syspaths-8.0.21-1.el7.aarch64.rpm rh-mysql80-mysql-debuginfo-8.0.21-1.el7.aarch64.rpm rh-mysql80-mysql-devel-8.0.21-1.el7.aarch64.rpm rh-mysql80-mysql-errmsg-8.0.21-1.el7.aarch64.rpm rh-mysql80-mysql-server-8.0.21-1.el7.aarch64.rpm rh-mysql80-mysql-server-syspaths-8.0.21-1.el7.aarch64.rpm rh-mysql80-mysql-syspaths-8.0.21-1.el7.aarch64.rpm rh-mysql80-mysql-test-8.0.21-1.el7.aarch64.rpm
ppc64le: rh-mysql80-mysql-8.0.21-1.el7.ppc64le.rpm rh-mysql80-mysql-common-8.0.21-1.el7.ppc64le.rpm rh-mysql80-mysql-config-8.0.21-1.el7.ppc64le.rpm rh-mysql80-mysql-config-syspaths-8.0.21-1.el7.ppc64le.rpm rh-mysql80-mysql-debuginfo-8.0.21-1.el7.ppc64le.rpm rh-mysql80-mysql-devel-8.0.21-1.el7.ppc64le.rpm rh-mysql80-mysql-errmsg-8.0.21-1.el7.ppc64le.rpm rh-mysql80-mysql-server-8.0.21-1.el7.ppc64le.rpm rh-mysql80-mysql-server-syspaths-8.0.21-1.el7.ppc64le.rpm rh-mysql80-mysql-syspaths-8.0.21-1.el7.ppc64le.rpm rh-mysql80-mysql-test-8.0.21-1.el7.ppc64le.rpm
s390x: rh-mysql80-mysql-8.0.21-1.el7.s390x.rpm

Read the Full Advisory


Severity
important
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2020:3518-01
Product: Red Hat Software Collections
Issue date: 2020-08-19

Topic

An update for rh-mysql80-mysql is now available for Red Hat SoftwareCollections.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.

Relevant Releases Architectures

Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) - aarch64, ppc64le, s390x, x86_64

Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6) - ppc64le, s390x, x86_64

Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7) - ppc64le, s390x, x86_64

Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) - x86_64

Bugs Fixed

1764675 - CVE-2019-2911 mysql: Information Schema unspecified vulnerability (CPU Oct 2019)

1764676 - CVE-2019-2914 mysql: Server: Security: Encryption unspecified vulnerability (CPU Oct 2019)

1764680 - CVE-2019-2938 mysql: InnoDB unspecified vulnerability (CPU Oct 2019)

1764681 - CVE-2019-2946 mysql: Server: PS unspecified vulnerability (CPU Oct 2019)

1764684 - CVE-2019-2957 mysql: Server: Security: Encryption unspecified vulnerability (CPU Oct 2019)

1764685 - CVE-2019-2960 mysql: Server: Replication unspecified vulnerability (CPU Oct 2019)

1764686 - CVE-2019-2963 mysql: InnoDB unspecified vulnerability (CPU Oct 2019)

1764687 - CVE-2019-2966 mysql: Server: Optimizer unspecified vulnerability (CPU Oct 2019)

1764688 - CVE-2019-2967 mysql: Server: Optimizer unspecified vulnerability (CPU Oct 2019)

1764689 - CVE-2019-2968 mysql: InnoDB unspecified vulnerability (CPU Oct 2019)

1764691 - CVE-2019-2974 mysql: Server: Optimizer unspecified vulnerability (CPU Oct 2019)

1764692 - CVE-2019-2982 mysql: Server: Optimizer unspecified vulnerability (CPU Oct 2019)

1764693 - CVE-2019-2991 mysql: Server: Optimizer unspecified vulnerability (CPU Oct 2019)

1764694 - CVE-2019-2993 mysql: Server: C API unspecified vulnerability (CPU Oct 2019)

1764695 - CVE-2019-2997 mysql: Server: DDL unspecified vulnerability (CPU Oct 2019)

1764696 - CVE-2019-2998 mysql: Server: Optimizer unspecified vulnerability (CPU Oct 2019)

Read the Full Advisory

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here