Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 1 articles for you...
172

Ubuntu 24.10: USN-7102-1 moderate: MySQL security fixes at 8.0.40

Several security issues were fixed in MySQL.. ========================================================================== Ubuntu Security Notice USN-7102-1 November 12, 2024 mysql-8.0 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Several security issues were fixed in MySQL. Software Description: - mysql-8.0: MySQL database Details: Multiple security issues were discovered in MySQL and this update includes new upstream MySQL versions to fix these issues. MySQL has been updated to 8.0.40 in Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 24.10. In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Please see the following for more information: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-40.html https://www.oracle.com/security-alerts/cpuoct2024.html Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10 mysql-server-8.0 8.0.40-0ubuntu0.24.10.1 Ubuntu 24.04 LTS mysql-server-8.0 8.0.40-0ubuntu0.24.04.1 Ubuntu 22.04 LTS mysql-server-8.0 8.0.40-0ubuntu0.22.04.1 Ubuntu 20.04 LTS mysql-server-8.0 8.0.40-0ubuntu0.20.04.1 This update uses a new upstream release, which includes additional bug fixes. In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7102-1 CVE-2024-21193, CVE-2024-21194, CVE-2024-21196, CVE-2024-21197, CVE-2024-21198, CVE-2024-21199, CVE-2024-21201, CVE-2024-21212, CVE-2024-21213, CVE-2024-21219, CVE-2024-21230, CVE-2024-21231, CVE-2024-21236, CVE-2024-21237, CVE-2024-21239, CVE-2024-21241 PackageInformation: https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.40-0ubuntu0.24.10.1 https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.40-0ubuntu0.24.04.1 https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.40-0ubuntu0.22.04.1 https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.40-0ubuntu0.20.04.1 . Ubuntu MySQL patches address numerous security vulnerabilities; keep systems current to maintain ideal security standards.. MySQL Security Updates, Ubuntu 24.10, MySQL Database Management, Cloud Infrastructure. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 12, 2024 Important Ubuntu
89

Fedora 36: 2023-444ef2d5bb Low: PostgreSQL Security Notice

**MariaDB 10.5.18 & Galera 26.4.13** Release notes: https://mariadb.com/docs/release-notes/community-server/old-releases/mariadb-10-5-series/mariadb-10-5-18-release-notes . -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2022-333df1c4aa 2022-11-30 01:37:59.937647 -------------------------------------------------------------------------------- Name : mariadb Product : Fedora 35 Version : 10.5.18 Release : 1.fc35 URL : http://mariadb.org Summary : A very fast and robust SQL database server Description : MariaDB is a community developed fork from MySQL - a multi-user, multi-threaded SQL database server. It is a client/server implementation consisting of a server daemon (mariadbd) and many different client programs and libraries. The base package contains the standard MariaDB/MySQL client programs and utilities. -------------------------------------------------------------------------------- Update Information: **MariaDB 10.5.18 & Galera 26.4.13** Release notes: https://mariadb.com/docs/release-notes/community-server/old-releases/mariadb-10-5-series/mariadb-10-5-18-release-notes -------------------------------------------------------------------------------- ChangeLog: * Wed Nov 16 2022 Michal Schorm - 3:10.5.18-1 - Rebase to 10.5.18 - OpenSSL 3 patch upstreamed * Thu Jul 21 2022 Fedora Release Engineering - 3:10.5.16-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild * Mon Jun 13 2022 Michal Schorm - 3:10.5.16-2 - Release bump for rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2114892 - CVE-2022-32081 CVE-2022-32082 CVE-2022-32084 CVE-2022-32089 CVE-2022-32091 CVE-2022-38791 mariadb: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2114892 -------------------------------------------------------------------------------- This update can be installed withthe "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-333df1c4aa' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . PostgreSQL 13.5 in Ubuntu 21.10 brings improvements and enhancements, boosting database efficiency and safeguarding data integrity.. MariaDB Updates, Fedora Security, SQL Database Server, Database Improvements, Fedora Release Notes. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 29, 2022 Critical Fedora
172

Ubuntu 22.10, 22.04 LTS USN-5739-1 Critical: MariaDB Security Fix

Several security issues were fixed in MariaDB.. =========================================================================Ubuntu Security Notice USN-5739-1 November 23, 2022 mariadb-10.3, mariadb-10.6 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.10 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Several security issues were fixed in MariaDB. Software Description: - mariadb-10.6: MariaDB database - mariadb-10.3: MariaDB database Details: Several security issues were discovered in MariaDB and this update includes new upstream MariaDB versions to fix these issues. MariaDB has been updated to 10.3.37 in Ubuntu 20.04 LTS and to 10.6.11 in Ubuntu 22.04 LTS and Ubuntu 22.10. In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.10: mariadb-server 1:10.6.11-0ubuntu0.22.10.1 Ubuntu 22.04 LTS: mariadb-server 1:10.6.11-0ubuntu0.22.04.1 Ubuntu 20.04 LTS: mariadb-server 1:10.3.37-0ubuntu0.20.04.1 This update uses a new upstream release, which includes additional bug fixes. In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5739-1 CVE-2018-25032, CVE-2021-46669, CVE-2022-21427, CVE-2022-27376, CVE-2022-27377, CVE-2022-27378, CVE-2022-27379, CVE-2022-27380, CVE-2022-27381, CVE-2022-27382, CVE-2022-27383, CVE-2022-27384, CVE-2022-27386, CVE-2022-27387, CVE-2022-27444, CVE-2022-27445, CVE-2022-27446, CVE-2022-27447, CVE-2022-27448, CVE-2022-27449, CVE-2022-27451, CVE-2022-27452, CVE-2022-27455, CVE-2022-27456, CVE-2022-27457, CVE-2022-27458, CVE-2022-32081, CVE-2022-32082, CVE-2022-32083, CVE-2022-32084, CVE-2022-32085, CVE-2022-32086, CVE-2022-32087,CVE-2022-32088, CVE-2022-32089, CVE-2022-32091 Package Information: https://launchpad.net/ubuntu/+source/mariadb-10.6/1:10.6.11-0ubuntu0.22.10.1 https://launchpad.net/ubuntu/+source/mariadb-10.6/1:10.6.11-0ubuntu0.22.04.1 https://launchpad.net/ubuntu/+source/mariadb-10.3/1:10.3.37-0ubuntu0.20.04.1 . Critical advisory highlights vulnerabilities in PostgreSQL for Debian users. Safeguard your environment by applying the most recent updates.. MariaDB Security, Ubuntu Security Advisory, Database Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 23, 2022 Critical Ubuntu
172

Ubuntu: 3799-1 Important: MySQL Server Security Fixes Released

Several security issues were fixed in MySQL.. =========================================================================Ubuntu Security Notice USN-3799-1 October 23, 2018 mysql-5.5, mysql-5.7 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.10 - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in MySQL. Software Description: - mysql-5.7: MySQL database - mysql-5.5: MySQL database Details: Multiple security issues were discovered in MySQL and this update includes new upstream MySQL versions to fix these issues. MySQL has been updated to 5.5.62 in Ubuntu 14.04 LTS. Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 18.10 have been updated to MySQL 5.7.24. In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Please see the following for more information: http://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-62.html http://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-24.html https://www.oracle.com/security-alerts/cpuoct2018.html Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.10: mysql-server-5.7 5.7.24-0ubuntu0.18.10.1 Ubuntu 18.04 LTS: mysql-server-5.7 5.7.24-0ubuntu0.18.04.1 Ubuntu 16.04 LTS: mysql-server-5.7 5.7.24-0ubuntu0.16.04.1 Ubuntu 14.04 LTS: mysql-server-5.5 5.5.62-0ubuntu0.14.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3799-1 CVE-2018-3133, CVE-2018-3143, CVE-2018-3144, CVE-2018-3155, CVE-2018-3156, CVE-2018-3161, CVE-2018-3162, CVE-2018-3171, CVE-2018-3173, CVE-2018-3174, CVE-2018-3185, CVE-2018-3187, CVE-2018-3200, CVE-2018-3247, CVE-2018-3251,CVE-2018-3276, CVE-2018-3277, CVE-2018-3278, CVE-2018-3282, CVE-2018-3283, CVE-2018-3284 Package Information: https://launchpad.net/ubuntu/+source/mysql-5.7/5.7.24-0ubuntu0.18.10.1 https://launchpad.net/ubuntu/+source/mysql-5.7/5.7.24-0ubuntu0.18.04.1 https://launchpad.net/ubuntu/+source/mysql-5.7/5.7.24-0ubuntu0.16.04.1 https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.62-0ubuntu0.14.04.1 . Significant vulnerabilities in MySQL were addressed in Ubuntu's latest update to enhance system stability and functionality.. MySQL Security, Ubuntu Update, Database Fixes. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 23, 2018 Important Ubuntu
89

Fedora 26: 2017-a45fb81029 Critical: PostgreSQL Security Update

Per release notes: https://www.postgresql.org/docs/9.6/release-9-6-3.html. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-a45fb81029 2017-05-16 00:54:07.300222 --------------------------------------------------------------------------------Name : postgresql Product : Fedora 26 Version : 9.6.3 Release : 1.fc26 URL : https://www.postgresql.org/ Summary : PostgreSQL client programs Description : PostgreSQL is an advanced Object-Relational database management system (DBMS). The base postgresql package contains the client programs that you'll need to access a PostgreSQL DBMS server, as well as HTML documentation for the whole system. These client programs can be located on the same machine as the PostgreSQL server, or on a remote machine that accesses a PostgreSQL server over a network connection. The PostgreSQL server can be found in the postgresql-server sub-package. --------------------------------------------------------------------------------Update Information: Per release notes: https://www.postgresql.org/docs/9.6/release-9-6-3.html --------------------------------------------------------------------------------References: [ 1 ] Bug #1450115 - CVE-2017-7484 CVE-2017-7485 CVE-2017-7486 postgresql: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1450115 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade postgresql' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announcemailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Urgent patch released for MySQL on Ubuntu 18.04 targeting several vulnerabilities. Upgrade using APT immediately.. PostgreSQL Update,Fedora Security,Database Management. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 16, 2017 Critical Fedora
98

RHEL 5: RHSA-2014:0536-01 Moderate Threat of MySQL Denial of Service

Updated mysql55-mysql packages that fix several security issues are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having Moderate security impact. Common Vulnerability Scoring System (CVSS) base scores,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: mysql55-mysql security update Advisory ID: RHSA-2014:0536-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2014:0536.html Issue date: 2014-05-22 CVE Names: CVE-2014-0384 CVE-2014-2419 CVE-2014-2430 CVE-2014-2431 CVE-2014-2432 CVE-2014-2436 CVE-2014-2438 CVE-2014-2440 ==================================================================== 1. Summary: Updated mysql55-mysql packages that fix several security issues are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having Moderate security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: RHEL Desktop Workstation (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 3. Description: MySQL is a multi-user, multi-threaded SQL database server. It consists of the MySQL server daemon (mysqld) and many client programs and libraries. This update fixes several vulnerabilities in the MySQL database server. Information about these flaws can be found on the Oracle Critical Patch Update Advisory page, listed in the References section. (CVE-2014-2436, CVE-2014-2440, CVE-2014-0384, CVE-2014-2419, CVE-2014-2430, CVE-2014-2431, CVE-2014-2432, CVE-2014-2438) These updated packagesupgrade MySQL to version 5.5.37. Refer to the MySQL Release Notes listed in the References section for a complete list of changes. All MySQL users should upgrade to these updated packages, which correct these issues. After installing this update, the MySQL server daemon (mysqld) will be restarted automatically. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/site/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1088133 - CVE-2014-0384 mysql: unspecified DoS related to XML (CPU April 2014) 1088134 - CVE-2014-2419 mysql: unspecified DoS related to Partition (CPU April 2014) 1088143 - CVE-2014-2430 mysql: unspecified DoS related to Performance Schema (CPU April 2014) 1088146 - CVE-2014-2431 mysql: unspecified DoS related to Options (CPU April 2014) 1088179 - CVE-2014-2432 mysql: unspecified DoS related to Federated (CPU April 2014) 1088190 - CVE-2014-2436 mysql: unspecified vulnerability related to RBR (CPU April 2014) 1088191 - CVE-2014-2438 mysql: unspecified DoS related to Replication (CPU April 2014) 1088197 - CVE-2014-2440 mysql: unspecified vulnerability related to Client (CPU April 2014) 6. Package List: Red Hat Enterprise Linux Desktop (v. 5 client): Source: i386: mysql55-mysql-5.5.37-1.el5.i386.rpm mysql55-mysql-bench-5.5.37-1.el5.i386.rpm mysql55-mysql-debuginfo-5.5.37-1.el5.i386.rpm mysql55-mysql-libs-5.5.37-1.el5.i386.rpm mysql55-mysql-server-5.5.37-1.el5.i386.rpm mysql55-mysql-test-5.5.37-1.el5.i386.rpm x86_64: mysql55-mysql-5.5.37-1.el5.x86_64.rpm mysql55-mysql-bench-5.5.37-1.el5.x86_64.rpm mysql55-mysql-debuginfo-5.5.37-1.el5.x86_64.rpm mysql55-mysql-libs-5.5.37-1.el5.x86_64.rpm mysql55-mysql-server-5.5.37-1.el5.x86_64.rpm mysql55-mysql-test-5.5.37-1.el5.x86_64.rpm RHEL Desktop Workstation (v. 5client): Source: i386: mysql55-mysql-debuginfo-5.5.37-1.el5.i386.rpm mysql55-mysql-devel-5.5.37-1.el5.i386.rpm x86_64: mysql55-mysql-debuginfo-5.5.37-1.el5.i386.rpm mysql55-mysql-debuginfo-5.5.37-1.el5.x86_64.rpm mysql55-mysql-devel-5.5.37-1.el5.i386.rpm mysql55-mysql-devel-5.5.37-1.el5.x86_64.rpm Red Hat Enterprise Linux (v. 5server): Source: i386: mysql55-mysql-5.5.37-1.el5.i386.rpm mysql55-mysql-bench-5.5.37-1.el5.i386.rpm mysql55-mysql-debuginfo-5.5.37-1.el5.i386.rpm mysql55-mysql-devel-5.5.37-1.el5.i386.rpm mysql55-mysql-libs-5.5.37-1.el5.i386.rpm mysql55-mysql-server-5.5.37-1.el5.i386.rpm mysql55-mysql-test-5.5.37-1.el5.i386.rpm ia64: mysql55-mysql-5.5.37-1.el5.ia64.rpm mysql55-mysql-bench-5.5.37-1.el5.ia64.rpm mysql55-mysql-debuginfo-5.5.37-1.el5.ia64.rpm mysql55-mysql-devel-5.5.37-1.el5.ia64.rpm mysql55-mysql-libs-5.5.37-1.el5.ia64.rpm mysql55-mysql-server-5.5.37-1.el5.ia64.rpm mysql55-mysql-test-5.5.37-1.el5.ia64.rpm ppc: mysql55-mysql-5.5.37-1.el5.ppc.rpm mysql55-mysql-bench-5.5.37-1.el5.ppc.rpm mysql55-mysql-debuginfo-5.5.37-1.el5.ppc.rpm mysql55-mysql-debuginfo-5.5.37-1.el5.ppc64.rpm mysql55-mysql-devel-5.5.37-1.el5.ppc.rpm mysql55-mysql-devel-5.5.37-1.el5.ppc64.rpm mysql55-mysql-libs-5.5.37-1.el5.ppc.rpm mysql55-mysql-server-5.5.37-1.el5.ppc.rpm mysql55-mysql-test-5.5.37-1.el5.ppc.rpm s390x: mysql55-mysql-5.5.37-1.el5.s390x.rpm mysql55-mysql-bench-5.5.37-1.el5.s390x.rpm mysql55-mysql-debuginfo-5.5.37-1.el5.s390.rpm mysql55-mysql-debuginfo-5.5.37-1.el5.s390x.rpm mysql55-mysql-devel-5.5.37-1.el5.s390.rpm mysql55-mysql-devel-5.5.37-1.el5.s390x.rpm mysql55-mysql-libs-5.5.37-1.el5.s390x.rpm mysql55-mysql-server-5.5.37-1.el5.s390x.rpm mysql55-mysql-test-5.5.37-1.el5.s390x.rpm x86_64: mysql55-mysql-5.5.37-1.el5.x86_64.rpm mysql55-mysql-bench-5.5.37-1.el5.x86_64.rpm mysql55-mysql-debuginfo-5.5.37-1.el5.i386.rpm mysql55-mysql-debuginfo-5.5.37-1.el5.x86_64.rpm mysql55-mysql-devel-5.5.37-1.el5.i386.rpm mysql55-mysql-devel-5.5.37-1.el5.x86_64.rpm mysql55-mysql-libs-5.5.37-1.el5.x86_64.rpm mysql55-mysql-server-5.5.37-1.el5.x86_64.rpm mysql55-mysql-test-5.5.37-1.el5.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/#package 7.References: https://access.redhat.com/security/cve/CVE-2014-0384 https://access.redhat.com/security/cve/CVE-2014-2419 https://access.redhat.com/security/cve/CVE-2014-2430 https://access.redhat.com/security/cve/CVE-2014-2431 https://access.redhat.com/security/cve/CVE-2014-2432 https://access.redhat.com/security/cve/CVE-2014-2436 https://access.redhat.com/security/cve/CVE-2014-2438 https://access.redhat.com/security/cve/CVE-2014-2440 https://access.redhat.com/security/updates/classification/#moderate https://www.oracle.com/security-alerts/cpuapr2014.html 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2014 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4 (GNU/Linux) iD8DBQFTfjIMXlSAg2UNWIIRApr9AJ9iPG74zTlM7AsDJ3xSPoprADRDaQCeLvq1 +luZizZ8zfIt9QrNKb+150Y=x6+j -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Red Hat has released updates for mysql55-mysql packages addressing a number of significant security vulnerabilities. It is essential for all users to upgrade without delay.. MySQL Update, Red Hat DoS Issue, Red Hat Security, MySQL Security Update. . LinuxSecurity.com Team

Calendar%202 May 22, 2014 Red Hat
98

Red Hat 5: RHSA-2014:0536-01 Moderate MySQL DoS Security Advisory

Updated mysql55-mysql packages that fix several security issues are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having Moderate [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Moderate: mysql55-mysql security update Advisory ID: RHSA-2014:0536-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2014:0536.html Issue date: 2014-05-22 CVE Names: CVE-2014-0384 CVE-2014-2419 CVE-2014-2430 CVE-2014-2431 CVE-2014-2432 CVE-2014-2436 CVE-2014-2438 CVE-2014-2440 ==================================================================== 1. Summary: Updated mysql55-mysql packages that fix several security issues are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having Moderate security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: RHEL Desktop Workstation (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 3. Description: MySQL is a multi-user, multi-threaded SQL database server. It consists of the MySQL server daemon (mysqld) and many client programs and libraries. This update fixes several vulnerabilities in the MySQL database server. Information about these flaws can be found on the Oracle Critical Patch Update Advisory page, listed in the References section. (CVE-2014-2436, CVE-2014-2440, CVE-2014-0384, CVE-2014-2419, CVE-2014-2430, CVE-2014-2431, CVE-2014-2432, CVE-2014-2438) These updated packages upgrade MySQL to version 5.5.37. Refer to the MySQL Release Notes listed in the References section for acomplete list of changes. All MySQL users should upgrade to these updated packages, which correct these issues. After installing this update, the MySQL server daemon (mysqld) will be restarted automatically. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/site/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1088133 - CVE-2014-0384 mysql: unspecified DoS related to XML (CPU April 2014) 1088134 - CVE-2014-2419 mysql: unspecified DoS related to Partition (CPU April 2014) 1088143 - CVE-2014-2430 mysql: unspecified DoS related to Performance Schema (CPU April 2014) 1088146 - CVE-2014-2431 mysql: unspecified DoS related to Options (CPU April 2014) 1088179 - CVE-2014-2432 mysql: unspecified DoS related to Federated (CPU April 2014) 1088190 - CVE-2014-2436 mysql: unspecified vulnerability related to RBR (CPU April 2014) 1088191 - CVE-2014-2438 mysql: unspecified DoS related to Replication (CPU April 2014) 1088197 - CVE-2014-2440 mysql: unspecified vulnerability related to Client (CPU April 2014) 6. Package List: Red Hat Enterprise Linux Desktop (v. 5 client): Source: i386: mysql55-mysql-5.5.37-1.el5.i386.rpm mysql55-mysql-bench-5.5.37-1.el5.i386.rpm mysql55-mysql-debuginfo-5.5.37-1.el5.i386.rpm mysql55-mysql-libs-5.5.37-1.el5.i386.rpm mysql55-mysql-server-5.5.37-1.el5.i386.rpm mysql55-mysql-test-5.5.37-1.el5.i386.rpm x86_64: mysql55-mysql-5.5.37-1.el5.x86_64.rpm mysql55-mysql-bench-5.5.37-1.el5.x86_64.rpm mysql55-mysql-debuginfo-5.5.37-1.el5.x86_64.rpm mysql55-mysql-libs-5.5.37-1.el5.x86_64.rpm mysql55-mysql-server-5.5.37-1.el5.x86_64.rpm mysql55-mysql-test-5.5.37-1.el5.x86_64.rpm RHEL Desktop Workstation (v. 5client): Source: i386: mysql55-mysql-debuginfo-5.5.37-1.el5.i386.rpm mysql55-mysql-devel-5.5.37-1.el5.i386.rpm x86_64: mysql55-mysql-debuginfo-5.5.37-1.el5.i386.rpm mysql55-mysql-debuginfo-5.5.37-1.el5.x86_64.rpm mysql55-mysql-devel-5.5.37-1.el5.i386.rpm mysql55-mysql-devel-5.5.37-1.el5.x86_64.rpm Red Hat Enterprise Linux (v. 5server): Source: i386: mysql55-mysql-5.5.37-1.el5.i386.rpm mysql55-mysql-bench-5.5.37-1.el5.i386.rpm mysql55-mysql-debuginfo-5.5.37-1.el5.i386.rpm mysql55-mysql-devel-5.5.37-1.el5.i386.rpm mysql55-mysql-libs-5.5.37-1.el5.i386.rpm mysql55-mysql-server-5.5.37-1.el5.i386.rpm mysql55-mysql-test-5.5.37-1.el5.i386.rpm ia64: mysql55-mysql-5.5.37-1.el5.ia64.rpm mysql55-mysql-bench-5.5.37-1.el5.ia64.rpm mysql55-mysql-debuginfo-5.5.37-1.el5.ia64.rpm mysql55-mysql-devel-5.5.37-1.el5.ia64.rpm mysql55-mysql-libs-5.5.37-1.el5.ia64.rpm mysql55-mysql-server-5.5.37-1.el5.ia64.rpm mysql55-mysql-test-5.5.37-1.el5.ia64.rpm ppc: mysql55-mysql-5.5.37-1.el5.ppc.rpm mysql55-mysql-bench-5.5.37-1.el5.ppc.rpm mysql55-mysql-debuginfo-5.5.37-1.el5.ppc.rpm mysql55-mysql-debuginfo-5.5.37-1.el5.ppc64.rpm mysql55-mysql-devel-5.5.37-1.el5.ppc.rpm mysql55-mysql-devel-5.5.37-1.el5.ppc64.rpm mysql55-mysql-libs-5.5.37-1.el5.ppc.rpm mysql55-mysql-server-5.5.37-1.el5.ppc.rpm mysql55-mysql-test-5.5.37-1.el5.ppc.rpm s390x: mysql55-mysql-5.5.37-1.el5.s390x.rpm mysql55-mysql-bench-5.5.37-1.el5.s390x.rpm mysql55-mysql-debuginfo-5.5.37-1.el5.s390.rpm mysql55-mysql-debuginfo-5.5.37-1.el5.s390x.rpm mysql55-mysql-devel-5.5.37-1.el5.s390.rpm mysql55-mysql-devel-5.5.37-1.el5.s390x.rpm mysql55-mysql-libs-5.5.37-1.el5.s390x.rpm mysql55-mysql-server-5.5.37-1.el5.s390x.rpm mysql55-mysql-test-5.5.37-1.el5.s390x.rpm x86_64: mysql55-mysql-5.5.37-1.el5.x86_64.rpm mysql55-mysql-bench-5.5.37-1.el5.x86_64.rpm mysql55-mysql-debuginfo-5.5.37-1.el5.i386.rpm mysql55-mysql-debuginfo-5.5.37-1.el5.x86_64.rpm mysql55-mysql-devel-5.5.37-1.el5.i386.rpm mysql55-mysql-devel-5.5.37-1.el5.x86_64.rpm mysql55-mysql-libs-5.5.37-1.el5.x86_64.rpm mysql55-mysql-server-5.5.37-1.el5.x86_64.rpm mysql55-mysql-test-5.5.37-1.el5.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/#package 7.References: https://access.redhat.com/security/cve/CVE-2014-0384 https://access.redhat.com/security/cve/CVE-2014-2419 https://access.redhat.com/security/cve/CVE-2014-2430 https://access.redhat.com/security/cve/CVE-2014-2431 https://access.redhat.com/security/cve/CVE-2014-2432 https://access.redhat.com/security/cve/CVE-2014-2436 https://access.redhat.com/security/cve/CVE-2014-2438 https://access.redhat.com/security/cve/CVE-2014-2440 https://access.redhat.com/security/updates/classification/#moderate https://www.oracle.com/security-alerts/cpuapr2014.html https://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-37.html 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2014 Red Hat, Inc. . Several vulnerabilities have been corrected in the Red Hat mysql55-mysql packages, classified as moderate in severity. Users are advised to upgrade to ensure system security.. mysql55-mysql, Red Hat 5, database security, system update. . LinuxSecurity.com Team

Calendar%202 May 22, 2014 Red Hat
172

Ubuntu 12.10 USN-1807-1 Moderate: MySQL Security Issues Fixes

Several security issues were fixed in MySQL.. =========================================================================Ubuntu Security Notice USN-1807-1 April 25, 2013 mysql-5.1, mysql-5.5, mysql-dfsg-5.1 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.10 - Ubuntu 12.04 LTS - Ubuntu 11.10 - Ubuntu 10.04 LTS Summary: Several security issues were fixed in MySQL. Software Description: - mysql-5.5: MySQL database - mysql-5.1: MySQL database - mysql-dfsg-5.1: MySQL database Details: Multiple security issues were discovered in MySQL and this update includes new upstream MySQL versions to fix these issues. MySQL has been updated to 5.1.69 in Ubuntu 10.04 LTS and Ubuntu 11.10. Ubuntu 12.04 LTS and Ubuntu 12.10 have been updated to MySQL 5.5.31. In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Please see the following for more information: http://dev.mysql.com/doc/relnotes/mysql/5.1/en/news-5-1-69.html http://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-31.html https://www.oracle.com/security-alerts/cpuapr2013.html Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.10: mysql-server-5.5 5.5.31-0ubuntu0.12.10.1 Ubuntu 12.04 LTS: mysql-server-5.5 5.5.31-0ubuntu0.12.04.1 Ubuntu 11.10: mysql-server-5.1 5.1.69-0ubuntu0.11.10.1 Ubuntu 10.04 LTS: mysql-server-5.1 5.1.69-0ubuntu0.10.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1807-1 CVE-2012-0553, CVE-2012-4414, CVE-2012-5613, CVE-2012-5615, CVE-2012-5627, CVE-2013-1492, CVE-2013-1502, CVE-2013-1506, CVE-2013-1511, CVE-2013-1512, CVE-2013-1521, CVE-2013-1523, CVE-2013-1526, CVE-2013-1532, CVE-2013-1544, CVE-2013-1552, CVE-2013-1555,CVE-2013-1623, CVE-2013-1861, CVE-2013-2375, CVE-2013-2376, CVE-2013-2378, CVE-2013-2389, CVE-2013-2391, CVE-2013-2392 Package Information: https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.31-0ubuntu0.12.10.1 https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.31-0ubuntu0.12.04.1 https://launchpad.net/ubuntu/+source/mysql-5.1/5.1.69-0ubuntu0.11.10.1 https://launchpad.net/ubuntu/+source/mysql-dfsg-5.1/5.1.69-0ubuntu0.10.04.1 . A variety of enhancements and patches for PostgreSQL on Ubuntu systems improve both safety and efficiency.. MySQL Security Updates, Ubuntu Database Issues, MySQL Update Fixes. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 25, 2013 Important Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200