Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

SUSE 12-LTSS: 2018:1382-1 Important: MariaDB DoS Issues Fixed

suse
Calendar Grey May 23, 2018
Scroller Suse
SUSE Linux has released a Security Update that resolves 12 vulnerabilities in mariadb. Patches can be obtained for the compromised systems.
An update that fixes 12 vulnerabilities is now available

Summary

MariaDB was updated to 10.0.35 (bsc#1090518) Notable changes: * PCRE updated to 8.42 * XtraDB updated to 5.6.39-83.1 * TokuDB updated to 5.6.39-83.1 * InnoDB updated to 5.6.40 * The embedded server library now supports SSL when connecting to remote servers [bsc#1088681], [CVE-2018-2767] * MDEV-15249 - Crash in MVCC read after IMPORT TABLESPACE * MDEV-14988 - innodb_read_only tries to modify files if transactions were recovered in COMMITTED state * MDEV-14773 - DROP TABLE hangs for InnoDB table with FULLTEXT index * MDEV-15723 - Crash in INFORMATION_SCHEMA.INNODB_SYS_TABLES when accessing corrupted record * fixes for the following security vulnerabilities: CVE-2018-2782, CVE-2018-2784, CVE-2018-2787, CVE-2018-2766, CVE-2018-2755, CVE-2018-2819, CVE-2018-2817, CVE-2018-2761, CVE-2018-2781,

References

#1088681 #1090518

Cross- CVE-2018-2755 CVE-2018-2761 CVE-2018-2766

CVE-2018-2767 CVE-2018-2771 CVE-2018-2781

CVE-2018-2782 CVE-2018-2784 CVE-2018-2787

CVE-2018-2813 CVE-2018-2817 CVE-2018-2819

Affected Products:

SUSE Linux Enterprise Server 12-LTSS

https://www.suse.com/security/cve/CVE-2018-2755.html

https://www.suse.com/security/cve/CVE-2018-2761.html

https://www.suse.com/security/cve/CVE-2018-2766.html

https://www.suse.com/security/cve/CVE-2018-2767.html

https://www.suse.com/security/cve/CVE-2018-2771.html

https://www.suse.com/security/cve/CVE-2018-2781.html

https://www.suse.com/security/cve/CVE-2018-2782.html

https://www.suse.com/security/cve/CVE-2018-2784.html

https://www.suse.com/security/cve/CVE-2018-2787.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:1382-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.