Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE: 2022:3225-1 Important: Multiple Risk Fixes for Mariadb

suse
Calendar Grey September 9, 2022
Dist Suse Esm H88
Enhancements for PostgreSQL addressing several vulnerabilities, recommended for Ubuntu systems to maintain operational reliability and safeguard data.
An update that solves 10 vulnerabilities and has one errata is now available

Summary

This update for mariadb fixes the following issues: Update to 10.4.26: - CVE-2022-32089 (bsc#1201169) - CVE-2022-32081 (bsc#1201161) - CVE-2022-32091 (bsc#1201170) - CVE-2022-32084 (bsc#1201164) - CVE-2018-25032 (bsc#1197459) - CVE-2022-32088 (bsc#1201168) - CVE-2022-32087 (bsc#1201167) - CVE-2022-32086 (bsc#1201166) - CVE-2022-32085 (bsc#1201165) - CVE-2022-32083 (bsc#1201163) Bugfixes: - Update mysql-systemd-helper to be aware of custom group (bsc#1200105). External references: - https://mariadb.com/docs/release-notes/community-server/old-releases/release-notes-mariadb-10-4-series/mariadb-10426-release-notes - https://mariadb.com/docs/release-notes/community-server/changelogs/changelogs-mariadb-10-4-series/mariadb-10426-changelog

References

#1197459 #1200105 #1201161 #1201163 #1201164

#1201165 #1201166 #1201167 #1201168 #1201169

#1201170

Cross- CVE-2018-25032 CVE-2022-32081 CVE-2022-32083

CVE-2022-32084 CVE-2022-32085 CVE-2022-32086

CVE-2022-32087 CVE-2022-32088 CVE-2022-32089

CVE-2022-32091

CVSS scores:

CVE-2018-25032 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVE-2018-25032 (SUSE): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2022-32081 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVE-2022-32081 (SUSE): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

CVE-2022-32083 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVE-2022-32083 (SUSE): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2022:3225-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here