This update fixes the following security issues: * Logjam attack: mysql uses 512 bit dh groups in SSL [bnc#934789] * CVE-2015-3152: mysql --ssl does not enforce SSL [bnc#924663] * CVE-2014-8964: heap buffer overflow [bnc#906574] * CVE-2015-2325: heap buffer overflow in compile_branch() [bnc#924960] * CVE-2015-2326: heap buffer overflow in pcre_compile2() [bnc#924961] * CVE-2015-0501: unspecified vulnerability related to Server:Compiling (CPU April 2015) * CVE-2015-2571: unspecified vulnerability related to Server:Optimizer (CPU April 2015) * CVE-2015-0505: unspecified vulnerability related to Server:DDL (CPU April 2015) * CVE-2015-0499: unspecified vulnerability related to Server:Federated (CPU April 2015) * CVE-2015-2568: unspecified vulnerability related to
#906574 #919053 #919062 #920865 #920896 #921333
#924663 #924960 #924961 #934789 #936407 #936408
#936409
Cross- CVE-2014-8964 CVE-2015-0433 CVE-2015-0441
CVE-2015-0499 CVE-2015-0501 CVE-2015-0505
CVE-2015-2325 CVE-2015-2326 CVE-2015-2568
CVE-2015-2571 CVE-2015-2573 CVE-2015-3152
Affected Products:
SUSE Linux Enterprise Workstation Extension 12
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Desktop 12
https://www.suse.com/security/cve/CVE-2014-8964.html
https://www.suse.com/security/cve/CVE-2015-0433.html
https://www.suse.com/security/cve/CVE-2015-0441.html
https://www.suse.com/security/cve/CVE-2015-0499.html
https://www.suse.com/security/cve/CVE-2015-0501.html
Get the latest Linux and open source security news straight to your inbox.