Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE 2020:0527-1 Moderate: mariadb Fixes Client Crash and Path Issues

suse
Calendar Grey February 28, 2020
Dist Suse Esm H88
SUSE has issued a security update for MariaDB due to two critical vulnerabilities affecting OpenStack. Review the details and adhere to patching guidelines to secure your systems
An update that solves two vulnerabilities and has two fixes is now available

Summary

This update for mariadb fixes the following issues: MariaDB was updated to version 10.0.40-3 (bsc#1162388). Security issues fixed: - CVE-2020-2574: Fixed a difficult to exploit vulnerability that allowed an attacker to crash the client (bsc#1162388). - CVE-2019-18901: Fixed an unsafe path handling behavior in mysql-systemd-helper (bsc#1160895). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 8: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2020-527=1 - SUSE OpenStack Cloud 8: zypper in -t patch SUSE-OpenStack-Cloud-8-2020-527=1 - HPE Helion Openstack 8:

References

#1077717 #1160895 #1160912 #1162388

Cross- CVE-2019-18901 CVE-2020-2574

Affected Products:

SUSE OpenStack Cloud Crowbar 8

SUSE OpenStack Cloud 8

HPE Helion Openstack 8

https://www.suse.com/security/cve/CVE-2019-18901.html

https://www.suse.com/security/cve/CVE-2020-2574.html

https://bugzilla.suse.com/1077717

https://bugzilla.suse.com/1160895

https://bugzilla.suse.com/1160912

https://bugzilla.suse.com/1162388

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:0527-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here