Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

SUSE Linux: 2017:2035-1 Important: MariaDB DoS Security Advisory

suse
Calendar Grey August 3, 2017
Dist Suse Esm H88
Major SUSE enhancement resolves several security issues in mariadb, featuring key corrective measures and detailed upgrade guidance.
An update that fixes 5 vulnerabilities is now available

Summary

This MariaDB update to version 10.0.31 GA fixes the following issues: Security issues fixed: - CVE-2017-3308: Subcomponent: Server: DML: Easily "exploitable" vulnerability allows low privileged attacker with network access via multiple protocols to compromise MariaDB Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS). (bsc#1048715) - CVE-2017-3309: Subcomponent: Server: Optimizer: Easily "exploitable" vulnerability allows low privileged attacker with network access via multiple protocols to compromise MariaDB Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS). (bsc#1048715)

References

#1048715 #963041

Cross- CVE-2017-3308 CVE-2017-3309 CVE-2017-3453

CVE-2017-3456 CVE-2017-3464

Affected Products:

SUSE OpenStack Cloud 6

SUSE Linux Enterprise Workstation Extension 12-SP3

SUSE Linux Enterprise Workstation Extension 12-SP2

SUSE Linux Enterprise Software Development Kit 12-SP3

SUSE Linux Enterprise Software Development Kit 12-SP2

SUSE Linux Enterprise Server for SAP 12-SP1

SUSE Linux Enterprise Server for Raspberry Pi 12-SP2

SUSE Linux Enterprise Server 12-SP3

SUSE Linux Enterprise Server 12-SP2

SUSE Linux Enterprise Server 12-SP1-LTSS

SUSE Linux Enterprise Desktop 12-SP3

SUSE Linux Enterprise Desktop 12-SP2

https://www.suse.com/security/cve/CVE-2017-3308.html

https://www.suse.com/security/cve/CVE-2017-3309.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2017:2035-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here