Some security vulenarbilities have been fixed. Some bigger bugs in optimizer and replication engine have been found and fixed. See release notes for details. References: . MGASA-2022-0215 - Updated mariadb packages fix security vulnerability Publication date: 03 Jun 2022 URL: https://advisories.mageia.org/MGASA-2022-0215.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-27376, CVE-2022-27377, CVE-2022-27378, CVE-2022-27379, CVE-2022-27380, CVE-2022-27381, CVE-2022-27382, CVE-2022-27383, CVE-2022-27384, CVE-2022-27386, CVE-2022-27387, CVE-2022-27444, CVE-2022-27445, CVE-2022-27446, CVE-2022-27447, CVE-2022-27448, CVE-2022-27449 Some security vulenarbilities have been fixed. Some bigger bugs in optimizer and replication engine have been found and fixed. See release notes for details. References: - https://bugs.mageia.org/show_bug.cgi?id=30460 - https://mariadb.com/docs/release-notes/community-server/old-releases/mariadb-10-5-series/mariadb-10516-release-notes - https://www.cve.org/CVERecord?id=CVE-2022-27376 - https://www.cve.org/CVERecord?id=CVE-2022-27377 - https://www.cve.org/CVERecord?id=CVE-2022-27378 - https://www.cve.org/CVERecord?id=CVE-2022-27379 - https://www.cve.org/CVERecord?id=CVE-2022-27380 - https://www.cve.org/CVERecord?id=CVE-2022-27381 - https://www.cve.org/CVERecord?id=CVE-2022-27382 - https://www.cve.org/CVERecord?id=CVE-2022-27383 - https://www.cve.org/CVERecord?id=CVE-2022-27384 - https://www.cve.org/CVERecord?id=CVE-2022-27386 - https://www.cve.org/CVERecord?id=CVE-2022-27387 - https://www.cve.org/CVERecord?id=CVE-2022-27444 - https://www.cve.org/CVERecord?id=CVE-2022-27445 - https://www.cve.org/CVERecord?id=CVE-2022-27446 - https://www.cve.org/CVERecord?id=CVE-2022-27447 - https://www.cve.org/CVERecord?id=CVE-2022-27448 - https://www.cve.org/CVERecord?id=CVE-2022-27449 SRPMS: - 8/core/mariadb-10.5.16-1.mga8 . Latest mariadb updates tackle vulnerabilities in both the optimizer and replicationfeatures for Mageia 8. More information available in the advisory.. Mageia Security Update, MariaDB Issues, Optimizer Fix. . LinuxSecurity.com Team
An update that solves three vulnerabilities and has one errata is now available. . SUSE Security Update: Security update for samba ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:0223-1 Rating: moderate References: #1141320 #1160850 #1160852 #1160888 Cross-References: CVE-2019-14902 CVE-2019-14907 CVE-2019-19344 Affected Products: SUSE Linux Enterprise Module for Python2 15-SP1 SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 SUSE Linux Enterprise Module for Basesystem 15-SP1 SUSE Linux Enterprise High Availability 15-SP1 SUSE Enterprise Storage 6 ______________________________________________________________________________ An update that solves three vulnerabilities and has one errata is now available. Description: This update for samba fixes the following issues: Security issues fixed: - CVE-2019-14907: Fixed a Server-side crash after charset conversion failure during NTLMSSP processing (bsc#1160888). - CVE-2019-14902: Fixed an issue where automatic replication of ACLs down subtree on AD Directory is not working (bsc#1160850). - CVE-2019-19344: Fixed a server crash when using dns zone scavenging yes (bsc#1160852). Non-security issue fixed: - Fixed Ceph snapshot path handling relative to root (bsc#1141320). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Python2 15-SP1: zypper in -t patch SUSE-SLE-Module-Python2-15-SP1-2020-223=1 - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1: zypper in -t patch SUSE-SLE-Module-Development-Tools-OBS-15-SP1-2020-223=1 - SUSE LinuxEnterprise Module for Basesystem 15-SP1: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP1-2020-223=1 - SUSE Linux Enterprise High Availability 15-SP1: zypper in -t patch SUSE-SLE-Product-HA-15-SP1-2020-223=1 - SUSE Enterprise Storage 6: zypper in -t patch SUSE-Storage-6-2020-223=1 Package List: - SUSE Linux Enterprise Module for Python2 15-SP1 (aarch64 ppc64le s390x x86_64): libsamba-policy0-4.9.5+git.243.e76c5cb3d97-3.21.1 libsamba-policy0-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 samba-ad-dc-4.9.5+git.243.e76c5cb3d97-3.21.1 samba-ad-dc-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 samba-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 samba-debugsource-4.9.5+git.243.e76c5cb3d97-3.21.1 samba-dsdb-modules-4.9.5+git.243.e76c5cb3d97-3.21.1 samba-dsdb-modules-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 samba-libs-python-4.9.5+git.243.e76c5cb3d97-3.21.1 samba-libs-python-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 samba-python-4.9.5+git.243.e76c5cb3d97-3.21.1 samba-python-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 (aarch64 ppc64le s390x x86_64): ctdb-pcp-pmda-4.9.5+git.243.e76c5cb3d97-3.21.1 ctdb-pcp-pmda-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 ctdb-tests-4.9.5+git.243.e76c5cb3d97-3.21.1 ctdb-tests-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 libsamba-policy-python-devel-4.9.5+git.243.e76c5cb3d97-3.21.1 samba-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 samba-debugsource-4.9.5+git.243.e76c5cb3d97-3.21.1 samba-test-4.9.5+git.243.e76c5cb3d97-3.21.1 samba-test-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 (aarch64 x86_64): samba-ceph-4.9.5+git.243.e76c5cb3d97-3.21.1 samba-ceph-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 - SUSE Linux Enterprise Module for Open Buildservice Development Tools15-SP1 (x86_64): libdcerpc-samr0-32bit-4.9.5+git.243.e76c5cb3d97-3.21.1 libdcerpc-samr0-32bit-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 libsamba-policy0-32bit-4.9.5+git.243.e76c5cb3d97-3.21.1 libsamba-policy0-32bit-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 libsamba-policy0-python3-32bit-4.9.5+git.243.e76c5cb3d97-3.21.1 libsamba-policy0-python3-32bit-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 libsmbclient0-32bit-4.9.5+git.243.e76c5cb3d97-3.21.1 libsmbclient0-32bit-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 samba-ad-dc-32bit-4.9.5+git.243.e76c5cb3d97-3.21.1 samba-ad-dc-32bit-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 samba-client-32bit-4.9.5+git.243.e76c5cb3d97-3.21.1 samba-client-32bit-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 samba-libs-python-32bit-4.9.5+git.243.e76c5cb3d97-3.21.1 samba-libs-python-32bit-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 samba-libs-python3-32bit-4.9.5+git.243.e76c5cb3d97-3.21.1 samba-libs-python3-32bit-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 (noarch): samba-doc-4.9.5+git.243.e76c5cb3d97-3.21.1 - SUSE Linux Enterprise Module for Basesystem 15-SP1 (aarch64 ppc64le s390x x86_64): libdcerpc-binding0-4.9.5+git.243.e76c5cb3d97-3.21.1 libdcerpc-binding0-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 libdcerpc-devel-4.9.5+git.243.e76c5cb3d97-3.21.1 libdcerpc-samr-devel-4.9.5+git.243.e76c5cb3d97-3.21.1 libdcerpc-samr0-4.9.5+git.243.e76c5cb3d97-3.21.1 libdcerpc-samr0-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 libdcerpc0-4.9.5+git.243.e76c5cb3d97-3.21.1 libdcerpc0-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 libndr-devel-4.9.5+git.243.e76c5cb3d97-3.21.1 libndr-krb5pac-devel-4.9.5+git.243.e76c5cb3d97-3.21.1 libndr-krb5pac0-4.9.5+git.243.e76c5cb3d97-3.21.1 libndr-krb5pac0-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 libndr-nbt-devel-4.9.5+git.243.e76c5cb3d97-3.21.1 libndr-nbt0-4.9.5+git.243.e76c5cb3d97-3.21.1 libndr-nbt0-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 libndr-standard-devel-4.9.5+git.243.e76c5cb3d97-3.21.1 libndr-standard0-4.9.5+git.243.e76c5cb3d97-3.21.1 libndr-standard0-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 libndr0-4.9.5+git.243.e76c5cb3d97-3.21.1 libndr0-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 libnetapi-devel-4.9.5+git.243.e76c5cb3d97-3.21.1 libnetapi0-4.9.5+git.243.e76c5cb3d97-3.21.1 libnetapi0-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 libsamba-credentials-devel-4.9.5+git.243.e76c5cb3d97-3.21.1 libsamba-credentials0-4.9.5+git.243.e76c5cb3d97-3.21.1 libsamba-credentials0-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 libsamba-errors-devel-4.9.5+git.243.e76c5cb3d97-3.21.1 libsamba-errors0-4.9.5+git.243.e76c5cb3d97-3.21.1 libsamba-errors0-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 libsamba-hostconfig-devel-4.9.5+git.243.e76c5cb3d97-3.21.1 libsamba-hostconfig0-4.9.5+git.243.e76c5cb3d97-3.21.1 libsamba-hostconfig0-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 libsamba-passdb-devel-4.9.5+git.243.e76c5cb3d97-3.21.1 libsamba-passdb0-4.9.5+git.243.e76c5cb3d97-3.21.1 libsamba-passdb0-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 libsamba-policy-devel-4.9.5+git.243.e76c5cb3d97-3.21.1 libsamba-policy-python3-devel-4.9.5+git.243.e76c5cb3d97-3.21.1 libsamba-policy0-python3-4.9.5+git.243.e76c5cb3d97-3.21.1 libsamba-policy0-python3-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 libsamba-util-devel-4.9.5+git.243.e76c5cb3d97-3.21.1 libsamba-util0-4.9.5+git.243.e76c5cb3d97-3.21.1 libsamba-util0-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 libsamdb-devel-4.9.5+git.243.e76c5cb3d97-3.21.1 libsamdb0-4.9.5+git.243.e76c5cb3d97-3.21.1 libsamdb0-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 libsmbclient-devel-4.9.5+git.243.e76c5cb3d97-3.21.1 libsmbclient0-4.9.5+git.243.e76c5cb3d97-3.21.1 libsmbclient0-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 libsmbconf-devel-4.9.5+git.243.e76c5cb3d97-3.21.1 libsmbconf0-4.9.5+git.243.e76c5cb3d97-3.21.1 libsmbconf0-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 libsmbldap-devel-4.9.5+git.243.e76c5cb3d97-3.21.1 libsmbldap2-4.9.5+git.243.e76c5cb3d97-3.21.1 libsmbldap2-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 libtevent-util-devel-4.9.5+git.243.e76c5cb3d97-3.21.1 libtevent-util0-4.9.5+git.243.e76c5cb3d97-3.21.1 libtevent-util0-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 libwbclient-devel-4.9.5+git.243.e76c5cb3d97-3.21.1 libwbclient0-4.9.5+git.243.e76c5cb3d97-3.21.1 libwbclient0-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 samba-4.9.5+git.243.e76c5cb3d97-3.21.1 samba-client-4.9.5+git.243.e76c5cb3d97-3.21.1 samba-client-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 samba-core-devel-4.9.5+git.243.e76c5cb3d97-3.21.1 samba-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 samba-debugsource-4.9.5+git.243.e76c5cb3d97-3.21.1 samba-libs-4.9.5+git.243.e76c5cb3d97-3.21.1 samba-libs-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 samba-libs-python3-4.9.5+git.243.e76c5cb3d97-3.21.1 samba-libs-python3-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 samba-python3-4.9.5+git.243.e76c5cb3d97-3.21.1 samba-python3-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 samba-winbind-4.9.5+git.243.e76c5cb3d97-3.21.1 samba-winbind-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 - SUSE Linux Enterprise Module for Basesystem 15-SP1 (x86_64): libdcerpc-binding0-32bit-4.9.5+git.243.e76c5cb3d97-3.21.1 libdcerpc-binding0-32bit-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 libdcerpc0-32bit-4.9.5+git.243.e76c5cb3d97-3.21.1 libdcerpc0-32bit-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 libndr-krb5pac0-32bit-4.9.5+git.243.e76c5cb3d97-3.21.1 libndr-krb5pac0-32bit-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 libndr-nbt0-32bit-4.9.5+git.243.e76c5cb3d97-3.21.1 libndr-nbt0-32bit-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 libndr-standard0-32bit-4.9.5+git.243.e76c5cb3d97-3.21.1 libndr-standard0-32bit-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 libndr0-32bit-4.9.5+git.243.e76c5cb3d97-3.21.1 libndr0-32bit-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 libnetapi0-32bit-4.9.5+git.243.e76c5cb3d97-3.21.1 libnetapi0-32bit-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 libsamba-credentials0-32bit-4.9.5+git.243.e76c5cb3d97-3.21.1 libsamba-credentials0-32bit-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 libsamba-errors0-32bit-4.9.5+git.243.e76c5cb3d97-3.21.1 libsamba-errors0-32bit-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 libsamba-hostconfig0-32bit-4.9.5+git.243.e76c5cb3d97-3.21.1 libsamba-hostconfig0-32bit-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 libsamba-passdb0-32bit-4.9.5+git.243.e76c5cb3d97-3.21.1 libsamba-passdb0-32bit-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 libsamba-util0-32bit-4.9.5+git.243.e76c5cb3d97-3.21.1 libsamba-util0-32bit-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 libsamdb0-32bit-4.9.5+git.243.e76c5cb3d97-3.21.1 libsamdb0-32bit-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 libsmbconf0-32bit-4.9.5+git.243.e76c5cb3d97-3.21.1 libsmbconf0-32bit-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 libsmbldap2-32bit-4.9.5+git.243.e76c5cb3d97-3.21.1 libsmbldap2-32bit-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 libtevent-util0-32bit-4.9.5+git.243.e76c5cb3d97-3.21.1 libtevent-util0-32bit-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 libwbclient0-32bit-4.9.5+git.243.e76c5cb3d97-3.21.1 libwbclient0-32bit-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 samba-libs-32bit-4.9.5+git.243.e76c5cb3d97-3.21.1 samba-libs-32bit-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 samba-winbind-32bit-4.9.5+git.243.e76c5cb3d97-3.21.1 samba-winbind-32bit-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 - SUSE Linux Enterprise High Availability 15-SP1 (aarch64 ppc64le s390x x86_64): ctdb-4.9.5+git.243.e76c5cb3d97-3.21.1 ctdb-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 samba-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 samba-debugsource-4.9.5+git.243.e76c5cb3d97-3.21.1 - SUSE Enterprise Storage 6 (aarch64 x86_64): samba-ceph-4.9.5+git.243.e76c5cb3d97-3.21.1 samba-ceph-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 samba-debuginfo-4.9.5+git.243.e76c5cb3d97-3.21.1 samba-debugsource-4.9.5+git.243.e76c5cb3d97-3.21.1 References: https://www.suse.com/security/cve/CVE-2019-14902.html https://www.suse.com/security/cve/CVE-2019-14907.html https://www.suse.com/security/cve/CVE-2019-19344.html https://bugzilla.suse.com/1141320 https://bugzilla.suse.com/1160850 https://bugzilla.suse.com/1160852 https://bugzilla.suse.com/1160888 _______________________________________________ sle-security-updates mailing list
An update for rh-mysql56-mysql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: rh-mysql56-mysql security update Advisory ID: RHSA-2018:1254-01 Product: Red Hat Software Collections Advisory URL: https://access.redhat.com/errata/RHSA-2018:1254 Issue date: 2018-04-26 CVE Names: CVE-2018-2755 CVE-2018-2758 CVE-2018-2761 CVE-2018-2766 CVE-2018-2771 CVE-2018-2773 CVE-2018-2781 CVE-2018-2782 CVE-2018-2784 CVE-2018-2787 CVE-2018-2805 CVE-2018-2813 CVE-2018-2817 CVE-2018-2818 CVE-2018-2819 ==================================================================== 1. Summary: An update for rh-mysql56-mysql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 6) - x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) - x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 6.7) - x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.3) - x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.4) - x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.5) - x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 6) - x86_64 Red Hat Software Collectionsfor Red Hat Enterprise Linux Workstation (v. 7) - x86_64 3. Description: MySQL is a multi-user, multi-threaded SQL database server. It consists of the MySQL server daemon, mysqld, and many client programs. The following packages have been upgraded to a later upstream version: rh-mysql56-mysql (5.6.40). (BZ#1571242) Security Fix(es): * mysql: Server: Replication unspecified vulnerability (CPU Apr 2018) (CVE-2018-2755) * mysql: Server: Security: Privileges unspecified vulnerability (CPU Apr 2018) (CVE-2018-2758) * mysql: Client programs unspecified vulnerability (CPU Apr 2018) (CVE-2018-2761) * mysql: InnoDB unspecified vulnerability (CPU Apr 2018) (CVE-2018-2766) * mysql: Server: Locking unspecified vulnerability (CPU Apr 2018) (CVE-2018-2771) * mysql: Client programs unspecified vulnerability (CPU Apr 2018) (CVE-2018-2773) * mysql: Server: Optimizer unspecified vulnerability (CPU Apr 2018) (CVE-2018-2781) * mysql: InnoDB unspecified vulnerability (CPU Apr 2018) (CVE-2018-2782) * mysql: InnoDB unspecified vulnerability (CPU Apr 2018) (CVE-2018-2784) * mysql: InnoDB unspecified vulnerability (CPU Apr 2018) (CVE-2018-2787) * mysql: GIS Extension unspecified vulnerability (CPU Apr 2018) (CVE-2018-2805) * mysql: Server: DDL unspecified vulnerability (CPU Apr 2018) (CVE-2018-2813) * mysql: Server: DDL unspecified vulnerability (CPU Apr 2018) (CVE-2018-2817) * mysql: Server : Security : Privileges unspecified vulnerability (CPU Apr 2018) (CVE-2018-2818) * mysql: InnoDB unspecified vulnerability (CPU Apr 2018) (CVE-2018-2819) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing this update, the MySQL server daemon (mysqld) will be restarted automatically. 5. Bugs fixed(https://bugzilla.redhat.com/): 1568921 - CVE-2018-2755 mysql: Server: Replication unspecified vulnerability (CPU Apr 2018) 1568922 - CVE-2018-2758 mysql: Server: Security: Privileges unspecified vulnerability (CPU Apr 2018) 1568924 - CVE-2018-2761 mysql: Client programs unspecified vulnerability (CPU Apr 2018) 1568926 - CVE-2018-2766 mysql: InnoDB unspecified vulnerability (CPU Apr 2018) 1568931 - CVE-2018-2771 mysql: Server: Locking unspecified vulnerability (CPU Apr 2018) 1568932 - CVE-2018-2773 mysql: Client programs unspecified vulnerability (CPU Apr 2018) 1568942 - CVE-2018-2781 mysql: Server: Optimizer unspecified vulnerability (CPU Apr 2018) 1568943 - CVE-2018-2782 mysql: InnoDB unspecified vulnerability (CPU Apr 2018) 1568944 - CVE-2018-2784 mysql: InnoDB unspecified vulnerability (CPU Apr 2018) 1568946 - CVE-2018-2787 mysql: InnoDB unspecified vulnerability (CPU Apr 2018) 1568948 - CVE-2018-2805 mysql: GIS Extension unspecified vulnerability (CPU Apr 2018) 1568951 - CVE-2018-2813 mysql: Server: DDL unspecified vulnerability (CPU Apr 2018) 1568954 - CVE-2018-2817 mysql: Server: DDL unspecified vulnerability (CPU Apr 2018) 1568955 - CVE-2018-2818 mysql: Server : Security : Privileges unspecified vulnerability (CPU Apr 2018) 1568956 - CVE-2018-2819 mysql: InnoDB unspecified vulnerability (CPU Apr 2018) 6. Package List: Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 6): Source: rh-mysql56-mysql-5.6.40-1.el6.src.rpm x86_64: rh-mysql56-mysql-5.6.40-1.el6.x86_64.rpm rh-mysql56-mysql-bench-5.6.40-1.el6.x86_64.rpm rh-mysql56-mysql-common-5.6.40-1.el6.x86_64.rpm rh-mysql56-mysql-config-5.6.40-1.el6.x86_64.rpm rh-mysql56-mysql-debuginfo-5.6.40-1.el6.x86_64.rpm rh-mysql56-mysql-devel-5.6.40-1.el6.x86_64.rpm rh-mysql56-mysql-errmsg-5.6.40-1.el6.x86_64.rpm rh-mysql56-mysql-server-5.6.40-1.el6.x86_64.rpm rh-mysql56-mysql-test-5.6.40-1.el6.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v.6.7): Source: rh-mysql56-mysql-5.6.40-1.el6.src.rpm x86_64: rh-mysql56-mysql-5.6.40-1.el6.x86_64.rpm rh-mysql56-mysql-bench-5.6.40-1.el6.x86_64.rpm rh-mysql56-mysql-common-5.6.40-1.el6.x86_64.rpm rh-mysql56-mysql-config-5.6.40-1.el6.x86_64.rpm rh-mysql56-mysql-debuginfo-5.6.40-1.el6.x86_64.rpm rh-mysql56-mysql-devel-5.6.40-1.el6.x86_64.rpm rh-mysql56-mysql-errmsg-5.6.40-1.el6.x86_64.rpm rh-mysql56-mysql-server-5.6.40-1.el6.x86_64.rpm rh-mysql56-mysql-test-5.6.40-1.el6.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 6): Source: rh-mysql56-mysql-5.6.40-1.el6.src.rpm x86_64: rh-mysql56-mysql-5.6.40-1.el6.x86_64.rpm rh-mysql56-mysql-bench-5.6.40-1.el6.x86_64.rpm rh-mysql56-mysql-common-5.6.40-1.el6.x86_64.rpm rh-mysql56-mysql-config-5.6.40-1.el6.x86_64.rpm rh-mysql56-mysql-debuginfo-5.6.40-1.el6.x86_64.rpm rh-mysql56-mysql-devel-5.6.40-1.el6.x86_64.rpm rh-mysql56-mysql-errmsg-5.6.40-1.el6.x86_64.rpm rh-mysql56-mysql-server-5.6.40-1.el6.x86_64.rpm rh-mysql56-mysql-test-5.6.40-1.el6.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7): Source: rh-mysql56-mysql-5.6.40-1.el7.src.rpm x86_64: rh-mysql56-mysql-5.6.40-1.el7.x86_64.rpm rh-mysql56-mysql-bench-5.6.40-1.el7.x86_64.rpm rh-mysql56-mysql-common-5.6.40-1.el7.x86_64.rpm rh-mysql56-mysql-config-5.6.40-1.el7.x86_64.rpm rh-mysql56-mysql-debuginfo-5.6.40-1.el7.x86_64.rpm rh-mysql56-mysql-devel-5.6.40-1.el7.x86_64.rpm rh-mysql56-mysql-errmsg-5.6.40-1.el7.x86_64.rpm rh-mysql56-mysql-server-5.6.40-1.el7.x86_64.rpm rh-mysql56-mysql-test-5.6.40-1.el7.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v.7.3): Source: rh-mysql56-mysql-5.6.40-1.el7.src.rpm x86_64: rh-mysql56-mysql-5.6.40-1.el7.x86_64.rpm rh-mysql56-mysql-bench-5.6.40-1.el7.x86_64.rpm rh-mysql56-mysql-common-5.6.40-1.el7.x86_64.rpm rh-mysql56-mysql-config-5.6.40-1.el7.x86_64.rpm rh-mysql56-mysql-debuginfo-5.6.40-1.el7.x86_64.rpm rh-mysql56-mysql-devel-5.6.40-1.el7.x86_64.rpm rh-mysql56-mysql-errmsg-5.6.40-1.el7.x86_64.rpm rh-mysql56-mysql-server-5.6.40-1.el7.x86_64.rpm rh-mysql56-mysql-test-5.6.40-1.el7.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.4): Source: rh-mysql56-mysql-5.6.40-1.el7.src.rpm x86_64: rh-mysql56-mysql-5.6.40-1.el7.x86_64.rpm rh-mysql56-mysql-bench-5.6.40-1.el7.x86_64.rpm rh-mysql56-mysql-common-5.6.40-1.el7.x86_64.rpm rh-mysql56-mysql-config-5.6.40-1.el7.x86_64.rpm rh-mysql56-mysql-debuginfo-5.6.40-1.el7.x86_64.rpm rh-mysql56-mysql-devel-5.6.40-1.el7.x86_64.rpm rh-mysql56-mysql-errmsg-5.6.40-1.el7.x86_64.rpm rh-mysql56-mysql-server-5.6.40-1.el7.x86_64.rpm rh-mysql56-mysql-test-5.6.40-1.el7.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.5): Source: rh-mysql56-mysql-5.6.40-1.el7.src.rpm x86_64: rh-mysql56-mysql-5.6.40-1.el7.x86_64.rpm rh-mysql56-mysql-bench-5.6.40-1.el7.x86_64.rpm rh-mysql56-mysql-common-5.6.40-1.el7.x86_64.rpm rh-mysql56-mysql-config-5.6.40-1.el7.x86_64.rpm rh-mysql56-mysql-debuginfo-5.6.40-1.el7.x86_64.rpm rh-mysql56-mysql-devel-5.6.40-1.el7.x86_64.rpm rh-mysql56-mysql-errmsg-5.6.40-1.el7.x86_64.rpm rh-mysql56-mysql-server-5.6.40-1.el7.x86_64.rpm rh-mysql56-mysql-test-5.6.40-1.el7.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v.7): Source: rh-mysql56-mysql-5.6.40-1.el7.src.rpm x86_64: rh-mysql56-mysql-5.6.40-1.el7.x86_64.rpm rh-mysql56-mysql-bench-5.6.40-1.el7.x86_64.rpm rh-mysql56-mysql-common-5.6.40-1.el7.x86_64.rpm rh-mysql56-mysql-config-5.6.40-1.el7.x86_64.rpm rh-mysql56-mysql-debuginfo-5.6.40-1.el7.x86_64.rpm rh-mysql56-mysql-devel-5.6.40-1.el7.x86_64.rpm rh-mysql56-mysql-errmsg-5.6.40-1.el7.x86_64.rpm rh-mysql56-mysql-server-5.6.40-1.el7.x86_64.rpm rh-mysql56-mysql-test-5.6.40-1.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2018-2755 https://access.redhat.com/security/cve/CVE-2018-2758 https://access.redhat.com/security/cve/CVE-2018-2761 https://access.redhat.com/security/cve/CVE-2018-2766 https://access.redhat.com/security/cve/CVE-2018-2771 https://access.redhat.com/security/cve/CVE-2018-2773 https://access.redhat.com/security/cve/CVE-2018-2781 https://access.redhat.com/security/cve/CVE-2018-2782 https://access.redhat.com/security/cve/CVE-2018-2784 https://access.redhat.com/security/cve/CVE-2018-2787 https://access.redhat.com/security/cve/CVE-2018-2805 https://access.redhat.com/security/cve/CVE-2018-2813 https://access.redhat.com/security/cve/CVE-2018-2817 https://access.redhat.com/security/cve/CVE-2018-2818 https://access.redhat.com/security/cve/CVE-2018-2819 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2018 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFa4X9OXlSAg2UNWIIRApq6AJ9oFnUHgKzSCLN1EMmewojQjQ2/ggCfU22c cwDZ/E1Q78nsNUW9fMNlqrE=vVSl -----END PGP SIGNATURE----- -- RHSA-announce mailing list
**Update to 10.1.30** sysusers and tmpfiles added by upstream **Release notes:** https://mariadb.com/docs/release-notes/community-server/old-releases/release-notes-mariadb-10-1-series/mariadb-10130-release-notes **CVE's fixed:** CVE-2017-15365. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-0d6a80f496 2018-01-23 21:16:49.690345 --------------------------------------------------------------------------------Name : mariadb Product : Fedora 26 Version : 10.1.30 Release : 1.fc26 URL : http://mariadb.org Summary : A community developed branch of MySQL Description : MariaDB is a community developed branch of MySQL. MariaDB is a multi-user, multi-threaded SQL database server. It is a client/server implementation consisting of a server daemon (mysqld) and many different client programs and libraries. The base package contains the standard MariaDB/MySQL client programs and generic MySQL files. --------------------------------------------------------------------------------Update Information: **Update to 10.1.30** sysusers and tmpfiles added by upstream **Release notes:** https://mariadb.com/docs/release-notes/community-server/old-releases/release-notes-mariadb-10-1-series/mariadb-10130-release-notes **CVE's fixed:** CVE-2017-15365 --------------------------------------------------------------------------------References: [ 1 ] Bug #1524235 - CVE-2017-15365 mariadb: Replication in sql/event_data_objects.cc occurs before ACL checks [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1524235 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade mariadb' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora ProjectGPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.