Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update for rh-mysql56-mysql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Important: rh-mysql56-mysql security update Advisory ID: RHSA-2017:3265-01 Product: Red Hat Software Collections Advisory URL: https://access.redhat.com/errata/RHSA-2017:3265 Issue date: 2017-11-27 CVE Names: CVE-2017-10155 CVE-2017-10227 CVE-2017-10268 CVE-2017-10276 CVE-2017-10279 CVE-2017-10283 CVE-2017-10286 CVE-2017-10294 CVE-2017-10314 CVE-2017-10378 CVE-2017-10379 CVE-2017-10384 ==================================================================== 1. Summary: An update for rh-mysql56-mysql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 6) - x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) - x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 6.7) - x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.3) - x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.4) - x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 6) - x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) - x86_64 3. Description: MySQL is a multi-user, multi-threaded SQL database server. Itconsists of the MySQL server daemon, mysqld, and many client programs. The following packages have been upgraded to a later upstream version: rh-mysql56-mysql (5.6.38). (BZ#1505112) Security Fix(es): * This update fixes several vulnerabilities in the MySQL database server. Information about these flaws can be found on the Oracle Critical Patch Update Advisory page listed in the References section. (CVE-2017-10155, CVE-2017-10227, CVE-2017-10268, CVE-2017-10276, CVE-2017-10279, CVE-2017-10283, CVE-2017-10286, CVE-2017-10294, CVE-2017-10314, CVE-2017-10378, CVE-2017-10379, CVE-2017-10384) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing this update, the MySQL server daemon (mysqld) will be restarted automatically. 5. Bugs fixed (https://bugzilla.redhat.com/): 1503649 - CVE-2017-10155 mysql: Server: Pluggable Auth unspecified vulnerability (CPU Oct 2017) 1503654 - CVE-2017-10227 mysql: Server: Optimizer unspecified vulnerability (CPU Oct 2017) 1503656 - CVE-2017-10268 mysql: Server: Replication unspecified vulnerability (CPU Oct 2017) 1503659 - CVE-2017-10276 mysql: Server: FTS unspecified vulnerability (CPU Oct 2017) 1503663 - CVE-2017-10279 mysql: Server: Optimizer unspecified vulnerability (CPU Oct 2017) 1503664 - CVE-2017-10283 mysql: Server: Performance Schema unspecified vulnerability (CPU Oct 2017) 1503669 - CVE-2017-10286 mysql: Server: InnoDB unspecified vulnerability (CPU Oct 2017) 1503671 - CVE-2017-10294 mysql: Server: Optimizer unspecified vulnerability (CPU Oct 2017) 1503679 - CVE-2017-10314 mysql: Server: Memcached unspecified vulnerability (CPU Oct 2017) 1503684 - CVE-2017-10378 mysql: Server: Optimizer unspecified vulnerability (CPU Oct 2017) 1503685 - CVE-2017-10379 mysql: Client programs unspecified vulnerability (CPU Oct 2017) 1503686 - CVE-2017-10384 mysql: Server: DDL unspecified vulnerability (CPU Oct 2017) 6. Package List: Red Hat Software Collections forRed Hat Enterprise Linux Server (v. 6): Source: rh-mysql56-mysql-5.6.38-1.el6.src.rpm x86_64: rh-mysql56-mysql-5.6.38-1.el6.x86_64.rpm rh-mysql56-mysql-bench-5.6.38-1.el6.x86_64.rpm rh-mysql56-mysql-common-5.6.38-1.el6.x86_64.rpm rh-mysql56-mysql-config-5.6.38-1.el6.x86_64.rpm rh-mysql56-mysql-debuginfo-5.6.38-1.el6.x86_64.rpm rh-mysql56-mysql-devel-5.6.38-1.el6.x86_64.rpm rh-mysql56-mysql-errmsg-5.6.38-1.el6.x86_64.rpm rh-mysql56-mysql-server-5.6.38-1.el6.x86_64.rpm rh-mysql56-mysql-test-5.6.38-1.el6.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 6.7): Source: rh-mysql56-mysql-5.6.38-1.el6.src.rpm x86_64: rh-mysql56-mysql-5.6.38-1.el6.x86_64.rpm rh-mysql56-mysql-bench-5.6.38-1.el6.x86_64.rpm rh-mysql56-mysql-common-5.6.38-1.el6.x86_64.rpm rh-mysql56-mysql-config-5.6.38-1.el6.x86_64.rpm rh-mysql56-mysql-debuginfo-5.6.38-1.el6.x86_64.rpm rh-mysql56-mysql-devel-5.6.38-1.el6.x86_64.rpm rh-mysql56-mysql-errmsg-5.6.38-1.el6.x86_64.rpm rh-mysql56-mysql-server-5.6.38-1.el6.x86_64.rpm rh-mysql56-mysql-test-5.6.38-1.el6.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 6): Source: rh-mysql56-mysql-5.6.38-1.el6.src.rpm x86_64: rh-mysql56-mysql-5.6.38-1.el6.x86_64.rpm rh-mysql56-mysql-bench-5.6.38-1.el6.x86_64.rpm rh-mysql56-mysql-common-5.6.38-1.el6.x86_64.rpm rh-mysql56-mysql-config-5.6.38-1.el6.x86_64.rpm rh-mysql56-mysql-debuginfo-5.6.38-1.el6.x86_64.rpm rh-mysql56-mysql-devel-5.6.38-1.el6.x86_64.rpm rh-mysql56-mysql-errmsg-5.6.38-1.el6.x86_64.rpm rh-mysql56-mysql-server-5.6.38-1.el6.x86_64.rpm rh-mysql56-mysql-test-5.6.38-1.el6.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server (v.7): Source: rh-mysql56-mysql-5.6.38-1.el7.src.rpm x86_64: rh-mysql56-mysql-5.6.38-1.el7.x86_64.rpm rh-mysql56-mysql-bench-5.6.38-1.el7.x86_64.rpm rh-mysql56-mysql-common-5.6.38-1.el7.x86_64.rpm rh-mysql56-mysql-config-5.6.38-1.el7.x86_64.rpm rh-mysql56-mysql-debuginfo-5.6.38-1.el7.x86_64.rpm rh-mysql56-mysql-devel-5.6.38-1.el7.x86_64.rpm rh-mysql56-mysql-errmsg-5.6.38-1.el7.x86_64.rpm rh-mysql56-mysql-server-5.6.38-1.el7.x86_64.rpm rh-mysql56-mysql-test-5.6.38-1.el7.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.3): Source: rh-mysql56-mysql-5.6.38-1.el7.src.rpm x86_64: rh-mysql56-mysql-5.6.38-1.el7.x86_64.rpm rh-mysql56-mysql-bench-5.6.38-1.el7.x86_64.rpm rh-mysql56-mysql-common-5.6.38-1.el7.x86_64.rpm rh-mysql56-mysql-config-5.6.38-1.el7.x86_64.rpm rh-mysql56-mysql-debuginfo-5.6.38-1.el7.x86_64.rpm rh-mysql56-mysql-devel-5.6.38-1.el7.x86_64.rpm rh-mysql56-mysql-errmsg-5.6.38-1.el7.x86_64.rpm rh-mysql56-mysql-server-5.6.38-1.el7.x86_64.rpm rh-mysql56-mysql-test-5.6.38-1.el7.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.4): Source: rh-mysql56-mysql-5.6.38-1.el7.src.rpm x86_64: rh-mysql56-mysql-5.6.38-1.el7.x86_64.rpm rh-mysql56-mysql-bench-5.6.38-1.el7.x86_64.rpm rh-mysql56-mysql-common-5.6.38-1.el7.x86_64.rpm rh-mysql56-mysql-config-5.6.38-1.el7.x86_64.rpm rh-mysql56-mysql-debuginfo-5.6.38-1.el7.x86_64.rpm rh-mysql56-mysql-devel-5.6.38-1.el7.x86_64.rpm rh-mysql56-mysql-errmsg-5.6.38-1.el7.x86_64.rpm rh-mysql56-mysql-server-5.6.38-1.el7.x86_64.rpm rh-mysql56-mysql-test-5.6.38-1.el7.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v.7): Source: rh-mysql56-mysql-5.6.38-1.el7.src.rpm x86_64: rh-mysql56-mysql-5.6.38-1.el7.x86_64.rpm rh-mysql56-mysql-bench-5.6.38-1.el7.x86_64.rpm rh-mysql56-mysql-common-5.6.38-1.el7.x86_64.rpm rh-mysql56-mysql-config-5.6.38-1.el7.x86_64.rpm rh-mysql56-mysql-debuginfo-5.6.38-1.el7.x86_64.rpm rh-mysql56-mysql-devel-5.6.38-1.el7.x86_64.rpm rh-mysql56-mysql-errmsg-5.6.38-1.el7.x86_64.rpm rh-mysql56-mysql-server-5.6.38-1.el7.x86_64.rpm rh-mysql56-mysql-test-5.6.38-1.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2017-10155 https://access.redhat.com/security/cve/CVE-2017-10227 https://access.redhat.com/security/cve/CVE-2017-10268 https://access.redhat.com/security/cve/CVE-2017-10276 https://access.redhat.com/security/cve/CVE-2017-10279 https://access.redhat.com/security/cve/CVE-2017-10283 https://access.redhat.com/security/cve/CVE-2017-10286 https://access.redhat.com/security/cve/CVE-2017-10294 https://access.redhat.com/security/cve/CVE-2017-10314 https://access.redhat.com/security/cve/CVE-2017-10378 https://access.redhat.com/security/cve/CVE-2017-10379 https://access.redhat.com/security/cve/CVE-2017-10384 https://access.redhat.com/security/updates/classification#important https://www.oracle.com/security-alerts/cpuoct2017.html https://dev.mysql.com/doc/relnotes/mysql/5.6/en/news-5-6-38.html 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2017 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFaHFxyXlSAg2UNWIIRArs4AKCtqJkkdgJedZBXj2fLS08MjvO+1wCfdwiE 7GdkIkP2TnZZdMunnC31G3I=B3om -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update that solves 13 vulnerabilities and has two fixes An update that solves 13 vulnerabilities and has two fixes An update that solves 13 vulnerabilities and has two fixes is now available. is now available.. openSUSE Security Update: Security update for mysql-community-server ______________________________________________________________________________ Announcement ID: openSUSE-SU-2017:2868-1 Rating: important References: #1039034 #1064096 #1064100 #1064101 #1064102 #1064104 #1064105 #1064107 #1064108 #1064112 #1064115 #1064116 #1064117 #1064118 #1064119 Cross-References: CVE-2017-10155 CVE-2017-10227 CVE-2017-10268 CVE-2017-10276 CVE-2017-10279 CVE-2017-10283 CVE-2017-10286 CVE-2017-10294 CVE-2017-10314 CVE-2017-10378 CVE-2017-10379 CVE-2017-10384 CVE-2017-3731 Affected Products: openSUSE Leap 42.3 openSUSE Leap 42.2 ______________________________________________________________________________ An update that solves 13 vulnerabilities and has two fixes is now available. Description: This update for mysql-community-server to 5.6.38 fixes the following issues: Full list of changes: http://dev.mysql.com/doc/relnotes/mysql/5.6/en/news-5-6-38.html CVEs fixed: - [boo#1064116] CVE-2017-10379 - [boo#1064117] CVE-2017-10384 - [boo#1064115] CVE-2017-10378 - [boo#1064101] CVE-2017-10268 - [boo#1064096] CVE-2017-10155 - [boo#1064118] CVE-2017-3731 - [boo#1064102] CVE-2017-10276 - [boo#1064105] CVE-2017-10283 - [boo#1064112] CVE-2017-10314 - [boo#1064100] CVE-2017-10227 - [boo#1064104] CVE-2017-10279 - [boo#1064108] CVE-2017-10294 - [boo#1064107] CVE-2017-10286 Additional changes: - add "BuildRequires: unixODBC-devel" to allow ODBC support for Connect engine [boo#1039034] - update filename in/var/adm/update-messages to match documentation, and build-compare pattern - some scripts from the tools subpackage, namely: wsrep_sst_xtrabackup, wsrep_sst_mariabackup.sh and wsrep_sst_xtrabackup-v2.sh need socat - fixed incorrect descriptions and mismatching RPM groups Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE Leap 42.3: zypper in -t patch openSUSE-2017-1196=1 - openSUSE Leap 42.2: zypper in -t patch openSUSE-2017-1196=1 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE Leap 42.3 (i586 x86_64): libmysql56client18-5.6.38-30.1 libmysql56client18-debuginfo-5.6.38-30.1 libmysql56client_r18-5.6.38-30.1 mysql-community-server-5.6.38-30.1 mysql-community-server-bench-5.6.38-30.1 mysql-community-server-bench-debuginfo-5.6.38-30.1 mysql-community-server-client-5.6.38-30.1 mysql-community-server-client-debuginfo-5.6.38-30.1 mysql-community-server-debuginfo-5.6.38-30.1 mysql-community-server-debugsource-5.6.38-30.1 mysql-community-server-test-5.6.38-30.1 mysql-community-server-test-debuginfo-5.6.38-30.1 mysql-community-server-tools-5.6.38-30.1 mysql-community-server-tools-debuginfo-5.6.38-30.1 - openSUSE Leap 42.3 (noarch): mysql-community-server-errormessages-5.6.38-30.1 - openSUSE Leap 42.3 (x86_64): libmysql56client18-32bit-5.6.38-30.1 libmysql56client18-debuginfo-32bit-5.6.38-30.1 libmysql56client_r18-32bit-5.6.38-30.1 - openSUSE Leap 42.2 (i586 x86_64): libmysql56client18-5.6.38-24.12.1 libmysql56client18-debuginfo-5.6.38-24.12.1 libmysql56client_r18-5.6.38-24.12.1 mysql-community-server-5.6.38-24.12.1 mysql-community-server-bench-5.6.38-24.12.1 mysql-community-server-bench-debuginfo-5.6.38-24.12.1 mysql-community-server-client-5.6.38-24.12.1 mysql-community-server-client-debuginfo-5.6.38-24.12.1 mysql-community-server-debuginfo-5.6.38-24.12.1 mysql-community-server-debugsource-5.6.38-24.12.1 mysql-community-server-test-5.6.38-24.12.1 mysql-community-server-test-debuginfo-5.6.38-24.12.1 mysql-community-server-tools-5.6.38-24.12.1 mysql-community-server-tools-debuginfo-5.6.38-24.12.1 - openSUSE Leap 42.2 (x86_64): libmysql56client18-32bit-5.6.38-24.12.1 libmysql56client18-debuginfo-32bit-5.6.38-24.12.1 libmysql56client_r18-32bit-5.6.38-24.12.1 - openSUSE Leap 42.2 (noarch): mysql-community-server-errormessages-5.6.38-24.12.1 References: https://www.suse.com/security/cve/CVE-2017-10155.html https://www.suse.com/security/cve/CVE-2017-10227.html https://www.suse.com/security/cve/CVE-2017-10268.html https://www.suse.com/security/cve/CVE-2017-10276.html https://www.suse.com/security/cve/CVE-2017-10279.html https://www.suse.com/security/cve/CVE-2017-10283.html https://www.suse.com/security/cve/CVE-2017-10286.html https://www.suse.com/security/cve/CVE-2017-10294.html https://www.suse.com/security/cve/CVE-2017-10314.html https://www.suse.com/security/cve/CVE-2017-10378.html https://www.suse.com/security/cve/CVE-2017-10379.html https://www.suse.com/security/cve/CVE-2017-10384.html https://www.suse.com/security/cve/CVE-2017-3731.html https://bugzilla.suse.com/1039034 https://bugzilla.suse.com/1064096 https://bugzilla.suse.com/1064100 https://bugzilla.suse.com/1064101 https://bugzilla.suse.com/1064102 https://bugzilla.suse.com/1064104 https://bugzilla.suse.com/1064105 https://bugzilla.suse.com/1064107 https://bugzilla.suse.com/1064108 https://bugzilla.suse.com/1064112 https://bugzilla.suse.com/1064115 https://bugzilla.suse.com/1064116 https://bugzilla.suse.com/1064117 https://bugzilla.suse.com/1064118 https://bugzilla.suse.com/1064119 . This enhancement addresses 15 significant vulnerabilities inpostgresql-server for Fedora, improving overall system robustness.. OpenSUSE Security, MySQL Update, Patch Instructions. . Severity: Important. LinuxSecurity.com Team
Important: mysql55-mysql security update. Date: Mon, 17 Nov 2014 14:50:57 +0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Pat Riehecky Subject: Security ERRATA Important: mysql55-mysql on SL5.x i386/x86_64 MIME-Version: 1.0 Synopsis: Important: mysql55-mysql security update Advisory ID: SLSA-2014:1859-1 Issue Date: 2014-11-17 CVE Numbers: CVE-2014-2494 CVE-2014-4207 CVE-2014-4243 CVE-2014-4258 CVE-2014-4260 CVE-2014-4274 CVE-2014-4287 CVE-2014-6463 CVE-2014-6464 CVE-2014-6469 CVE-2014-6484 CVE-2014-6505 CVE-2014-6507 CVE-2014-6520 CVE-2014-6530 CVE-2014-6551 CVE-2014-6555 CVE-2014-6559 -- This update fixes several vulnerabilities in the MySQL database server. Information about these flaws can be found on the Oracle Critical Patch Update Advisory page. (CVE-2014-2494, CVE-2014-4207, CVE-2014-4243, CVE-2014-4258, CVE-2014-4260, CVE-2014-4287, CVE-2014-4274, CVE-2014-6463, CVE-2014-6464, CVE-2014-6469, CVE-2014-6484, CVE-2014-6505, CVE-2014-6507, CVE-2014-6520, CVE-2014-6530, CVE-2014-6551, CVE-2014-6555, CVE-2014-6559) After installing this update, the MySQL server daemon (mysqld) will be restarted automatically. -- SL5 x86_64 mysql55-mysql-5.5.40-2.el5.x86_64.rpm mysql55-mysql-bench-5.5.40-2.el5.x86_64.rpm mysql55-mysql-debuginfo-5.5.40-2.el5.x86_64.rpm mysql55-mysql-libs-5.5.40-2.el5.x86_64.rpm mysql55-mysql-server-5.5.40-2.el5.x86_64.rpm mysql55-mysql-test-5.5.40-2.el5.x86_64.rpm mysql55-mysql-debuginfo-5.5.40-2.el5.i386.rpm mysql55-mysql-devel-5.5.40-2.el5.i386.rpm mysql55-mysql-devel-5.5.40-2.el5.x86_64.rpm i386 mysql55-mysql-5.5.40-2.el5.i386.rpm mysql55-mysql-bench-5.5.40-2.el5.i386.rpm mysql55-mysql-debuginfo-5.5.40-2.el5.i386.rpm mysql55-mysql-libs-5.5.40-2.el5.i386.rpm mysql55-mysql-server-5.5.40-2.el5.i386.rpm mysql55-mysql-test-5.5.40-2.el5.i386.rpm mysql55-mysql-devel-5.5.40-2.el5.i386.rpm - Scientific Linux Development Team . Addresses several security weaknesses in mysql55-mysql for Scientific Linux 5.xusers. Important patch released immediately.. mysql55-mysql Update, Scientific Linux Advisory, Important Security Update. . Severity: Important. LinuxSecurity.com Team
Updated mysql55-mysql packages that fix several security issues are now available for Red Hat Software Collections 1. The Red Hat Security Response Team has rated this update as having Moderate [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Moderate: mysql55-mysql security update Advisory ID: RHSA-2014:0537-01 Product: Red Hat Software Collections Advisory URL: https://access.redhat.com/errata/RHSA-2014:0537.html Issue date: 2014-05-22 CVE Names: CVE-2014-0384 CVE-2014-2419 CVE-2014-2430 CVE-2014-2431 CVE-2014-2432 CVE-2014-2436 CVE-2014-2438 CVE-2014-2440 ==================================================================== 1. Summary: Updated mysql55-mysql packages that fix several security issues are now available for Red Hat Software Collections 1. The Red Hat Security Response Team has rated this update as having Moderate security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Software Collections for RHEL 6 Server - x86_64 Red Hat Software Collections for RHEL 6 Workstation - x86_64 3. Description: MySQL is a multi-user, multi-threaded SQL database server. It consists of the MySQL server daemon (mysqld) and many client programs and libraries. This update fixes several vulnerabilities in the MySQL database server. Information about these flaws can be found on the Oracle Critical Patch Update Advisory page, listed in the References section. (CVE-2014-2436, CVE-2014-2440, CVE-2014-0384, CVE-2014-2419, CVE-2014-2430, CVE-2014-2431, CVE-2014-2432, CVE-2014-2438) These updated packages upgrade MySQL to version 5.5.37. Refer to the MySQL Release Notes listed in the References section for a complete list of changes. All MySQL users should upgrade to theseupdated packages, which correct these issues. After installing this update, the MySQL server daemon (mysqld) will be restarted automatically. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/site/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1088133 - CVE-2014-0384 mysql: unspecified DoS related to XML (CPU April 2014) 1088134 - CVE-2014-2419 mysql: unspecified DoS related to Partition (CPU April 2014) 1088143 - CVE-2014-2430 mysql: unspecified DoS related to Performance Schema (CPU April 2014) 1088146 - CVE-2014-2431 mysql: unspecified DoS related to Options (CPU April 2014) 1088179 - CVE-2014-2432 mysql: unspecified DoS related to Federated (CPU April 2014) 1088190 - CVE-2014-2436 mysql: unspecified vulnerability related to RBR (CPU April 2014) 1088191 - CVE-2014-2438 mysql: unspecified DoS related to Replication (CPU April 2014) 1088197 - CVE-2014-2440 mysql: unspecified vulnerability related to Client (CPU April 2014) 6. Package List: Red Hat Software Collections for RHEL 6 Server: Source: x86_64: mysql55-mysql-5.5.37-1.2.el6.x86_64.rpm mysql55-mysql-bench-5.5.37-1.2.el6.x86_64.rpm mysql55-mysql-debuginfo-5.5.37-1.2.el6.x86_64.rpm mysql55-mysql-devel-5.5.37-1.2.el6.x86_64.rpm mysql55-mysql-libs-5.5.37-1.2.el6.x86_64.rpm mysql55-mysql-server-5.5.37-1.2.el6.x86_64.rpm mysql55-mysql-test-5.5.37-1.2.el6.x86_64.rpm Red Hat Software Collections for RHEL 6 Workstation: Source: x86_64: mysql55-mysql-5.5.37-1.2.el6.x86_64.rpm mysql55-mysql-bench-5.5.37-1.2.el6.x86_64.rpm mysql55-mysql-debuginfo-5.5.37-1.2.el6.x86_64.rpm mysql55-mysql-devel-5.5.37-1.2.el6.x86_64.rpm mysql55-mysql-libs-5.5.37-1.2.el6.x86_64.rpm mysql55-mysql-server-5.5.37-1.2.el6.x86_64.rpm mysql55-mysql-test-5.5.37-1.2.el6.x86_64.rpm These packages are GPG signed by Red Hat for security. Ourkey and details on how to verify the signature are available from https://access.redhat.com/security/team/key/#package 7. References: https://access.redhat.com/security/cve/CVE-2014-0384 https://access.redhat.com/security/cve/CVE-2014-2419 https://access.redhat.com/security/cve/CVE-2014-2430 https://access.redhat.com/security/cve/CVE-2014-2431 https://access.redhat.com/security/cve/CVE-2014-2432 https://access.redhat.com/security/cve/CVE-2014-2436 https://access.redhat.com/security/cve/CVE-2014-2438 https://access.redhat.com/security/cve/CVE-2014-2440 https://access.redhat.com/security/updates/classification/#moderate https://www.oracle.com/security-alerts/cpuapr2014.html https://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-37.html 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2014 Red Hat, Inc. . The latest version of mysql55-mysql packages resolves vulnerabilities in Red Hat Software Collections, classified as a Moderate risk.. Red Hat Software Collections, mysql update, security patch, DoS issues. . LinuxSecurity.com Team
New mariadb and mysql packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix a security issue. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] mariadb, mysql (SSA:2014-050-02) New mariadb and mysql packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix a security issue. Here are the details from the Slackware 14.1 ChangeLog: +--------------------------+ patches/packages/mariadb-5.5.35-i486-1_slack14.1.txz: Upgraded. This update fixes a buffer overflow in the mysql command line client which may allow malicious or compromised database servers to cause a denial of service (crash) and possibly execute arbitrary code via a long server version string. For more information, see: https://www.cve.org/CVERecord?id=CVE-2014-0001 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 13.0: ftp://ftp.slackware.com/pub/slackware/slackware-13.0/patches/packages/mysql-5.0.96-i486-2_slack13.0.txz Updated package for Slackware x86_64 13.0: ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/packages/mysql-5.0.96-x86_64-2_slack13.0.txz Updated package for Slackware 13.1: ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/mysql-5.1.73-i486-1_slack13.1.txz Updated package for Slackware x86_64 13.1: ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/packages/mysql-5.1.73-x86_64-1_slack13.1.txz Updated package for Slackware 13.37: ftp://ftp.slackware.com/pub/slackware/slackware-13.37/patches/packages/mysql-5.1.73-i486-1_slack13.37.txz Updated package for Slackware x86_6413.37: ftp://ftp.slackware.com/pub/slackware/slackware64-13.37/patches/packages/mysql-5.1.73-x86_64-1_slack13.37.txz Updated package for Slackware 14.0: Updated package for Slackware x86_64 14.0: Updated package for Slackware 14.1: Updated package for Slackware x86_64 14.1: Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 13.0 package: 1cce4ce596cb9f42513d8a9916576af8 mysql-5.0.96-i486-2_slack13.0.txz Slackware x86_64 13.0 package: ef5a1237b6878d711a32b653bbae7cb5 mysql-5.0.96-x86_64-2_slack13.0.txz Slackware 13.1 package: 3f83cf2cf1d9aa42e4104b08abdc263b mysql-5.1.73-i486-1_slack13.1.txz Slackware x86_64 13.1 package: 6a8b07c70f5d20892316713853c27fa8 mysql-5.1.73-x86_64-1_slack13.1.txz Slackware 13.37 package: 58fa913ee68907884197c465e130a010 mysql-5.1.73-i486-1_slack13.37.txz Slackware x86_64 13.37 package: 8d2b940be5f141b9c2b0e0a43c67bf63 mysql-5.1.73-x86_64-1_slack13.37.txz Slackware 14.0 package: ac87007a1dd38d854fcdade3a2a42d03 mysql-5.5.36-i486-1_slack14.0.txz Slackware x86_64 14.0 package: c6c4ba0de7750bc23cab8be4b33f0716 mysql-5.5.36-x86_64-1_slack14.0.txz Slackware 14.1 package: 0e14c2b69128af4ff32b5bc760434ccb mariadb-5.5.35-i486-1_slack14.1.txz Slackware x86_64 14.1 package: 08890b91bb6e2db66c501a7a10e936a7 mariadb-5.5.35-x86_64-1_slack14.1.txz Slackware -current package: d085ede95618780ae8b78dfe51ab127d ap/mariadb-5.5.35-i486-1.txz Slackware x86_64 -current package: 305eba3dc795b5308a9f39e196323395 ap/mariadb-5.5.35-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg mariadb-5.5.35-i486-1_slack14.1.txz Then, restart the database server: # sh /etc/rc.d/rc.mysqld restart +-----+ . Fresh updates for mariadb and mysql packages rolled out for Slackware to mitigate a serious buffer overflow vulnerability and enhance overall security.. Slackware Security, Mysql Update, Mariadb Patch, Buffer Overflow Fix. . Severity: Critical.LinuxSecurity.com Team
Updated mysql55-mysql packages that fix several security issues are now available for Red Hat Software Collections 1. The Red Hat Security Response Team has rated this update as having moderate [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Moderate: mysql55-mysql security update Advisory ID: RHSA-2014:0173-01 Product: Red Hat Software Collections Advisory URL: https://access.redhat.com/errata/RHSA-2014:0173.html Issue date: 2014-02-13 CVE Names: CVE-2013-3839 CVE-2013-5807 CVE-2013-5891 CVE-2013-5908 CVE-2014-0001 CVE-2014-0386 CVE-2014-0393 CVE-2014-0401 CVE-2014-0402 CVE-2014-0412 CVE-2014-0420 CVE-2014-0437 ==================================================================== 1. Summary: Updated mysql55-mysql packages that fix several security issues are now available for Red Hat Software Collections 1. The Red Hat Security Response Team has rated this update as having moderate security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Software Collections for RHEL 6 Server - x86_64 Red Hat Software Collections for RHEL 6 Workstation - x86_64 3. Description: MySQL is a multi-user, multi-threaded SQL database server. It consists of the MySQL server daemon (mysqld) and many client programs and libraries. This update fixes several vulnerabilities in the MySQL database server. Information about these flaws can be found on the Oracle Critical Patch Update Advisory page, listed in the References section. (CVE-2013-5807, CVE-2013-5891, CVE-2014-0386, CVE-2014-0393, CVE-2014-0401, CVE-2014-0402, CVE-2014-0412, CVE-2014-0420, CVE-2014-0437, CVE-2013-3839, CVE-2013-5908) A buffer overflow flaw was found in the way the MySQL command lineclient tool (mysql) processed excessively long version strings. If a user connected to a malicious MySQL server via the mysql client, the server could use this flaw to crash the mysql client or, potentially, execute arbitrary code as the user running the mysql client. (CVE-2014-0001) The CVE-2014-0001 issue was discovered by Garth Mollett of the Red Hat Security Response Team. These updated packages upgrade MySQL to version 5.5.36. Refer to the MySQL Release Notes listed in the References section for a complete list of changes. All MySQL users should upgrade to these updated packages, which correct these issues. After installing this update, the MySQL server daemon (mysqld) will be restarted automatically. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/site/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1019978 - CVE-2013-3839 mysql: unspecified DoS related to Optimizer (CPU October 2013) 1019997 - CVE-2013-5807 mysql: unspecified flaw related to Replication (CPU October 2013) 1053371 - CVE-2013-5891 mysql: unspecified vulnerability related to Partition DoS (CPU Jan 2014) 1053373 - CVE-2013-5908 mysql: unspecified vulnerability related to Error Handling DoS (CPU Jan 2014) 1053375 - CVE-2014-0386 mysql: unspecified vulnerability related to Optimizer DoS (CPU Jan 2014) 1053377 - CVE-2014-0393 mysql: unspecified vulnerability related to InnoDB affecting integrity (CPU Jan 2014) 1053378 - CVE-2014-0401 mysql: unspecified DoS vulnerability (CPU Jan 2014) 1053380 - CVE-2014-0402 mysql: unspecified vulnerability related to Locking DoS (CPU Jan 2014) 1053381 - CVE-2014-0412 mysql: unspecified vulnerability related to InnoDB DoS (CPU Jan 2014) 1053383 - CVE-2014-0420 mysql: unspecified vulnerability related to Replication DoS (CPU Jan 2014) 1053390 - CVE-2014-0437mysql: unspecified vulnerability related to Optimizer DoS (CPU Jan 2014) 1054592 - CVE-2014-0001 mysql: command-line tool buffer overflow via long server version string 6. Package List: Red Hat Software Collections for RHEL 6 Server: Source: x86_64: mysql55-mysql-5.5.36-1.1.el6.x86_64.rpm mysql55-mysql-bench-5.5.36-1.1.el6.x86_64.rpm mysql55-mysql-debuginfo-5.5.36-1.1.el6.x86_64.rpm mysql55-mysql-devel-5.5.36-1.1.el6.x86_64.rpm mysql55-mysql-libs-5.5.36-1.1.el6.x86_64.rpm mysql55-mysql-server-5.5.36-1.1.el6.x86_64.rpm mysql55-mysql-test-5.5.36-1.1.el6.x86_64.rpm Red Hat Software Collections for RHEL 6 Workstation: Source: x86_64: mysql55-mysql-5.5.36-1.1.el6.x86_64.rpm mysql55-mysql-bench-5.5.36-1.1.el6.x86_64.rpm mysql55-mysql-debuginfo-5.5.36-1.1.el6.x86_64.rpm mysql55-mysql-devel-5.5.36-1.1.el6.x86_64.rpm mysql55-mysql-libs-5.5.36-1.1.el6.x86_64.rpm mysql55-mysql-server-5.5.36-1.1.el6.x86_64.rpm mysql55-mysql-test-5.5.36-1.1.el6.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/#package 7. References: https://access.redhat.com/security/cve/CVE-2013-3839 https://access.redhat.com/security/cve/CVE-2013-5807 https://access.redhat.com/security/cve/CVE-2013-5891 https://access.redhat.com/security/cve/CVE-2013-5908 https://access.redhat.com/security/cve/CVE-2014-0001 https://access.redhat.com/security/cve/CVE-2014-0386 https://access.redhat.com/security/cve/CVE-2014-0393 https://access.redhat.com/security/cve/CVE-2014-0401 https://access.redhat.com/security/cve/CVE-2014-0402 https://access.redhat.com/security/cve/CVE-2014-0412 https://access.redhat.com/security/cve/CVE-2014-0420 https://access.redhat.com/security/cve/CVE-2014-0437 https://access.redhat.com/security/updates/classification/#moderate https://www.oracle.com/security-alerts/cpujan2014.html https://www.oracle.com/security-alerts/cpuoct2013.html 8. Contact: The Red Hat security contact is . More contact detailsat https://access.redhat.com/security/team/contact/ Copyright 2014 Red Hat, Inc. . The advisory provided by Red Hat concerning mysql55-mysql highlights a number of moderate vulnerabilities that necessitate updates to improve security protocols.. mysql55-mysql, Red Hat Security, database security, security update, software patch. . LinuxSecurity.com Team
Updated mysql packages that fix several security issues are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having moderate security impact. Common Vulnerability Scoring System (CVSS) base scores,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: mysql security update Advisory ID: RHSA-2012:0127-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2012:0127.html Issue date: 2012-02-13 CVE Names: CVE-2012-0075 CVE-2012-0087 CVE-2012-0101 CVE-2012-0102 CVE-2012-0114 CVE-2012-0484 CVE-2012-0490 ==================================================================== 1. Summary: Updated mysql packages that fix several security issues are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having moderate security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: RHEL Desktop Workstation (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 3. Description: MySQL is a multi-user, multi-threaded SQL database server. It consists of the MySQL server daemon (mysqld) and many client programs and libraries. This update fixes several vulnerabilities in the MySQL database server. Information about these flaws can be found on the Oracle Critical Patch Update Advisory page, listed in the References section. (CVE-2012-0075, CVE-2012-0087, CVE-2012-0101, CVE-2012-0102, CVE-2012-0114, CVE-2012-0484, CVE-2012-0490) These updated packages upgrade MySQL to version 5.0.95. Refer to theMySQL release notes for a full list of changes: http://dev.mysql.com/doc/refman/5.0/en/news-5-0-x.html All MySQL users should upgrade to these updated packages, which correct these issues. After installing this update, the MySQL server daemon (mysqld) will be restarted automatically. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/kb/docs/DOC-11259 5. Bugs fixed (http://bugzilla.redhat.com/): 783794 - CVE-2012-0075 mysql: Unspecified vulnerability allows remote authenticated users to affect integrity 783795 - CVE-2012-0087 mysql: Unspecified vulnerability allows remote authenticated users to affect availability 783797 - CVE-2012-0101 mysql: Unspecified vulnerability allows remote authenticated users to affect availability 783798 - CVE-2012-0102 mysql: Unspecified vulnerability allows remote authenticated users to affect availability 783801 - CVE-2012-0114 mysql: Unspecified vulnerability allows local users to affect confidentiality and integrity 783808 - CVE-2012-0484 mysql: Unspecified vulnerability allows remote authenticated users to affect confidentiality 783815 - CVE-2012-0490 mysql: Unspecified vulnerability allows remote authenticated users to affect availability 6. Package List: Red Hat Enterprise Linux Desktop (v. 5 client): Source: i386: mysql-5.0.95-1.el5_7.1.i386.rpm mysql-debuginfo-5.0.95-1.el5_7.1.i386.rpm x86_64: mysql-5.0.95-1.el5_7.1.i386.rpm mysql-5.0.95-1.el5_7.1.x86_64.rpm mysql-debuginfo-5.0.95-1.el5_7.1.i386.rpm mysql-debuginfo-5.0.95-1.el5_7.1.x86_64.rpm RHEL Desktop Workstation (v. 5client): Source: i386: mysql-bench-5.0.95-1.el5_7.1.i386.rpm mysql-debuginfo-5.0.95-1.el5_7.1.i386.rpm mysql-devel-5.0.95-1.el5_7.1.i386.rpm mysql-server-5.0.95-1.el5_7.1.i386.rpm mysql-test-5.0.95-1.el5_7.1.i386.rpm x86_64: mysql-bench-5.0.95-1.el5_7.1.x86_64.rpm mysql-debuginfo-5.0.95-1.el5_7.1.i386.rpm mysql-debuginfo-5.0.95-1.el5_7.1.x86_64.rpm mysql-devel-5.0.95-1.el5_7.1.i386.rpm mysql-devel-5.0.95-1.el5_7.1.x86_64.rpm mysql-server-5.0.95-1.el5_7.1.x86_64.rpm mysql-test-5.0.95-1.el5_7.1.x86_64.rpm Red Hat Enterprise Linux (v. 5server): Source: i386: mysql-5.0.95-1.el5_7.1.i386.rpm mysql-bench-5.0.95-1.el5_7.1.i386.rpm mysql-debuginfo-5.0.95-1.el5_7.1.i386.rpm mysql-devel-5.0.95-1.el5_7.1.i386.rpm mysql-server-5.0.95-1.el5_7.1.i386.rpm mysql-test-5.0.95-1.el5_7.1.i386.rpm ia64: mysql-5.0.95-1.el5_7.1.i386.rpm mysql-5.0.95-1.el5_7.1.ia64.rpm mysql-bench-5.0.95-1.el5_7.1.ia64.rpm mysql-debuginfo-5.0.95-1.el5_7.1.i386.rpm mysql-debuginfo-5.0.95-1.el5_7.1.ia64.rpm mysql-devel-5.0.95-1.el5_7.1.ia64.rpm mysql-server-5.0.95-1.el5_7.1.ia64.rpm mysql-test-5.0.95-1.el5_7.1.ia64.rpm ppc: mysql-5.0.95-1.el5_7.1.ppc.rpm mysql-5.0.95-1.el5_7.1.ppc64.rpm mysql-bench-5.0.95-1.el5_7.1.ppc.rpm mysql-debuginfo-5.0.95-1.el5_7.1.ppc.rpm mysql-debuginfo-5.0.95-1.el5_7.1.ppc64.rpm mysql-devel-5.0.95-1.el5_7.1.ppc.rpm mysql-devel-5.0.95-1.el5_7.1.ppc64.rpm mysql-server-5.0.95-1.el5_7.1.ppc.rpm mysql-server-5.0.95-1.el5_7.1.ppc64.rpm mysql-test-5.0.95-1.el5_7.1.ppc.rpm s390x: mysql-5.0.95-1.el5_7.1.s390.rpm mysql-5.0.95-1.el5_7.1.s390x.rpm mysql-bench-5.0.95-1.el5_7.1.s390x.rpm mysql-debuginfo-5.0.95-1.el5_7.1.s390.rpm mysql-debuginfo-5.0.95-1.el5_7.1.s390x.rpm mysql-devel-5.0.95-1.el5_7.1.s390.rpm mysql-devel-5.0.95-1.el5_7.1.s390x.rpm mysql-server-5.0.95-1.el5_7.1.s390x.rpm mysql-test-5.0.95-1.el5_7.1.s390x.rpm x86_64: mysql-5.0.95-1.el5_7.1.i386.rpm mysql-5.0.95-1.el5_7.1.x86_64.rpm mysql-bench-5.0.95-1.el5_7.1.x86_64.rpm mysql-debuginfo-5.0.95-1.el5_7.1.i386.rpm mysql-debuginfo-5.0.95-1.el5_7.1.x86_64.rpm mysql-devel-5.0.95-1.el5_7.1.i386.rpm mysql-devel-5.0.95-1.el5_7.1.x86_64.rpm mysql-server-5.0.95-1.el5_7.1.x86_64.rpm mysql-test-5.0.95-1.el5_7.1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7.References: https://access.redhat.com/security/cve/CVE-2012-0075 https://access.redhat.com/security/cve/CVE-2012-0087 https://access.redhat.com/security/cve/CVE-2012-0101 https://access.redhat.com/security/cve/CVE-2012-0102 https://access.redhat.com/security/cve/CVE-2012-0114 https://access.redhat.com/security/cve/CVE-2012-0484 https://access.redhat.com/security/cve/CVE-2012-0490 https://access.redhat.com/security/updates/classification#moderate http://dev.mysql.com/doc/refman/5.0/en/news-5-0-x.html https://www.oracle.com/security-alerts/cpujan2012.html 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2012 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4 (GNU/Linux) iD8DBQFPOXTeXlSAg2UNWIIRAr2YAKCRLpwKgMfJlXZVnY0Q66eLxYzo3QCdGraW w6809/DA6haFduRlcOgldHU=xYMm -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list
Moderate: mysql security update. Date: Fri, 4 Mar 2011 14:40:38 -0600 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA Moderate: mysql on SL6.x i386/x86_64 Comments: To: "
Get the latest Linux and open source security news straight to your inbox.