SUSE Security Update: Security update for mysql
______________________________________________________________________________

Announcement ID:    SUSE-SU-2017:2996-1
Rating:             important
References:         #1064101 #1064115 #1064116 #1064117 #1064119 
                    
Cross-References:   CVE-2017-10268 CVE-2017-10378 CVE-2017-10379
                    CVE-2017-10384
Affected Products:
                    SUSE Linux Enterprise Software Development Kit 11-SP4
                    SUSE Linux Enterprise Server 11-SP4
                    SUSE Linux Enterprise Server 11-SP3-LTSS
                    SUSE Linux Enterprise Point of Sale 11-SP3
                    SUSE Linux Enterprise Debuginfo 11-SP4
                    SUSE Linux Enterprise Debuginfo 11-SP3
______________________________________________________________________________

   An update that solves four vulnerabilities and has one
   errata is now available.

Description:



   This update for mysql to version 5.5.58 fixes the following issues:

   Fixed security issues:

   - CVE-2017-10268: issue inside subcomponent Server Replication
     [bsc#1064101]
   - CVE-2017-10378: issue inside subcomponent Server Optimizer [bsc#1064115]
   - CVE-2017-10379: issue inside subcomponent Client programs [bsc#1064116]
   - CVE-2017-10384: issue inside subcomponent Server DDL [bsc#1064117]

   For a full list of changes check:

       http://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-58.html


Patch Instructions:

   To install this SUSE Security Update use YaST online_update.
   Alternatively you can run the command listed for your product:

   - SUSE Linux Enterprise Software Development Kit 11-SP4:

      zypper in -t patch sdksp4-mysql-13344=1

   - SUSE Linux Enterprise Server 11-SP4:

      zypper in -t patch slessp4-mysql-13344=1

   - SUSE Linux Enterprise Server 11-SP3-LTSS:

      zypper in -t patch slessp3-mysql-13344=1

   - SUSE Linux Enterprise Point of Sale 11-SP3:

      zypper in -t patch sleposp3-mysql-13344=1

   - SUSE Linux Enterprise Debuginfo 11-SP4:

      zypper in -t patch dbgsp4-mysql-13344=1

   - SUSE Linux Enterprise Debuginfo 11-SP3:

      zypper in -t patch dbgsp3-mysql-13344=1

   To bring your system up-to-date, use "zypper patch".


Package List:

   - SUSE Linux Enterprise Software Development Kit 11-SP4 (ppc64 s390x x86_64):

      libmysql55client_r18-32bit-5.5.58-0.39.6.1

   - SUSE Linux Enterprise Software Development Kit 11-SP4 (ia64):

      libmysql55client_r18-x86-5.5.58-0.39.6.1

   - SUSE Linux Enterprise Server 11-SP4 (i586 ia64 ppc64 s390x x86_64):

      libmysql55client18-5.5.58-0.39.6.1
      libmysql55client_r18-5.5.58-0.39.6.1
      mysql-5.5.58-0.39.6.1
      mysql-client-5.5.58-0.39.6.1
      mysql-tools-5.5.58-0.39.6.1

   - SUSE Linux Enterprise Server 11-SP4 (ppc64 s390x x86_64):

      libmysql55client18-32bit-5.5.58-0.39.6.1
      libmysql55client_r18-32bit-5.5.58-0.39.6.1

   - SUSE Linux Enterprise Server 11-SP4 (ia64):

      libmysql55client18-x86-5.5.58-0.39.6.1
      libmysql55client_r18-x86-5.5.58-0.39.6.1

   - SUSE Linux Enterprise Server 11-SP3-LTSS (i586 s390x x86_64):

      libmysql55client18-5.5.58-0.39.6.1
      libmysql55client_r18-5.5.58-0.39.6.1
      mysql-5.5.58-0.39.6.1
      mysql-client-5.5.58-0.39.6.1
      mysql-tools-5.5.58-0.39.6.1

   - SUSE Linux Enterprise Server 11-SP3-LTSS (s390x x86_64):

      libmysql55client18-32bit-5.5.58-0.39.6.1

   - SUSE Linux Enterprise Point of Sale 11-SP3 (i586):

      libmysql55client18-5.5.58-0.39.6.1
      libmysql55client_r18-5.5.58-0.39.6.1
      mysql-5.5.58-0.39.6.1
      mysql-client-5.5.58-0.39.6.1
      mysql-tools-5.5.58-0.39.6.1

   - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ia64 ppc64 s390x x86_64):

      mysql-debuginfo-5.5.58-0.39.6.1
      mysql-debugsource-5.5.58-0.39.6.1

   - SUSE Linux Enterprise Debuginfo 11-SP3 (i586 s390x x86_64):

      mysql-debuginfo-5.5.58-0.39.6.1
      mysql-debugsource-5.5.58-0.39.6.1


References:

   https://www.suse.com/security/cve/CVE-2017-10268.html
   https://www.suse.com/security/cve/CVE-2017-10378.html
   https://www.suse.com/security/cve/CVE-2017-10379.html
   https://www.suse.com/security/cve/CVE-2017-10384.html
   https://bugzilla.suse.com/1064101
   https://bugzilla.suse.com/1064115
   https://bugzilla.suse.com/1064116
   https://bugzilla.suse.com/1064117
   https://bugzilla.suse.com/1064119

SuSE: 2017:2996-1: important: mysql

November 11, 2017
An update that solves four vulnerabilities and has one An update that solves four vulnerabilities and has one An update that solves four vulnerabilities and has one errata is now a...

Summary

This update for mysql to version 5.5.58 fixes the following issues: Fixed security issues: - CVE-2017-10268: issue inside subcomponent Server Replication [bsc#1064101] - CVE-2017-10378: issue inside subcomponent Server Optimizer [bsc#1064115] - CVE-2017-10379: issue inside subcomponent Client programs [bsc#1064116] - CVE-2017-10384: issue inside subcomponent Server DDL [bsc#1064117] For a full list of changes check: http://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-58.html Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11-SP4: zypper in -t patch sdksp4-mysql-13344=1 - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-mysql-13344=1 - SUSE Linux Enterprise Server 11-SP3-LTSS: zypper in -t patch slessp3-mysql-13344=1 - SUSE Linux Enterprise Point of Sale 11-SP3: zypper in -t patch sleposp3-mysql-13344=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-mysql-13344=1 - SUSE Linux Enterprise Debuginfo 11-SP3: zypper in -t patch dbgsp3-mysql-13344=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 11-SP4 (ppc64 s390x x86_64): libmysql55client_r18-32bit-5.5.58-0.39.6.1 - SUSE Linux Enterprise Software Development Kit 11-SP4 (ia64): libmysql55client_r18-x86-5.5.58-0.39.6.1 - SUSE Linux Enterprise Server 11-SP4 (i586 ia64 ppc64 s390x x86_64): libmysql55client18-5.5.58-0.39.6.1 libmysql55client_r18-5.5.58-0.39.6.1 mysql-5.5.58-0.39.6.1 mysql-client-5.5.58-0.39.6.1 mysql-tools-5.5.58-0.39.6.1 - SUSE Linux Enterprise Server 11-SP4 (ppc64 s390x x86_64): libmysql55client18-32bit-5.5.58-0.39.6.1 libmysql55client_r18-32bit-5.5.58-0.39.6.1 - SUSE Linux Enterprise Server 11-SP4 (ia64): libmysql55client18-x86-5.5.58-0.39.6.1 libmysql55client_r18-x86-5.5.58-0.39.6.1 - SUSE Linux Enterprise Server 11-SP3-LTSS (i586 s390x x86_64): libmysql55client18-5.5.58-0.39.6.1 libmysql55client_r18-5.5.58-0.39.6.1 mysql-5.5.58-0.39.6.1 mysql-client-5.5.58-0.39.6.1 mysql-tools-5.5.58-0.39.6.1 - SUSE Linux Enterprise Server 11-SP3-LTSS (s390x x86_64): libmysql55client18-32bit-5.5.58-0.39.6.1 - SUSE Linux Enterprise Point of Sale 11-SP3 (i586): libmysql55client18-5.5.58-0.39.6.1 libmysql55client_r18-5.5.58-0.39.6.1 mysql-5.5.58-0.39.6.1 mysql-client-5.5.58-0.39.6.1 mysql-tools-5.5.58-0.39.6.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ia64 ppc64 s390x x86_64): mysql-debuginfo-5.5.58-0.39.6.1 mysql-debugsource-5.5.58-0.39.6.1 - SUSE Linux Enterprise Debuginfo 11-SP3 (i586 s390x x86_64): mysql-debuginfo-5.5.58-0.39.6.1 mysql-debugsource-5.5.58-0.39.6.1

References

#1064101 #1064115 #1064116 #1064117 #1064119

Cross- CVE-2017-10268 CVE-2017-10378 CVE-2017-10379

CVE-2017-10384

Affected Products:

SUSE Linux Enterprise Software Development Kit 11-SP4

SUSE Linux Enterprise Server 11-SP4

SUSE Linux Enterprise Server 11-SP3-LTSS

SUSE Linux Enterprise Point of Sale 11-SP3

SUSE Linux Enterprise Debuginfo 11-SP4

SUSE Linux Enterprise Debuginfo 11-SP3

https://www.suse.com/security/cve/CVE-2017-10268.html

https://www.suse.com/security/cve/CVE-2017-10378.html

https://www.suse.com/security/cve/CVE-2017-10379.html

https://www.suse.com/security/cve/CVE-2017-10384.html

https://bugzilla.suse.com/1064101

https://bugzilla.suse.com/1064115

https://bugzilla.suse.com/1064116

https://bugzilla.suse.com/1064117

https://bugzilla.suse.com/1064119

Severity
Announcement ID: SUSE-SU-2017:2996-1
Rating: important

Related News