An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for mariadb-100 ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:3370-1 Rating: moderate References: #1154162 Cross-References: CVE-2019-2974 Affected Products: SUSE Linux Enterprise Workstation Extension 12-SP5 SUSE Linux Enterprise Workstation Extension 12-SP4 SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Software Development Kit 12-SP4 SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server 12-SP4 SUSE Linux Enterprise Desktop 12-SP4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for mariadb-100 fixes the following issues: Security issue fixed: - CVE-2019-2974: Fixed Server Optimizer (bsc#1154162). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 12-SP5: zypper in -t patch SUSE-SLE-WE-12-SP5-2019-3370=1 - SUSE Linux Enterprise Workstation Extension 12-SP4: zypper in -t patch SUSE-SLE-WE-12-SP4-2019-3370=1 - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2019-3370=1 - SUSE Linux Enterprise Software Development Kit 12-SP4: zypper in -t patch SUSE-SLE-SDK-12-SP4-2019-3370=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2019-3370=1 - SUSE Linux Enterprise Server 12-SP4: zypper in -t patch SUSE-SLE-SERVER-12-SP4-2019-3370=1 - SUSE Linux Enterprise Desktop12-SP4: zypper in -t patch SUSE-SLE-DESKTOP-12-SP4-2019-3370=1 Package List: - SUSE Linux Enterprise Workstation Extension 12-SP5 (x86_64): libmysqlclient_r18-10.0.40.2-2.12.2 libmysqlclient_r18-32bit-10.0.40.2-2.12.2 mariadb-100-debuginfo-10.0.40.2-2.12.2 mariadb-100-debugsource-10.0.40.2-2.12.2 - SUSE Linux Enterprise Workstation Extension 12-SP4 (x86_64): libmysqlclient_r18-10.0.40.2-2.12.2 libmysqlclient_r18-32bit-10.0.40.2-2.12.2 mariadb-100-debuginfo-10.0.40.2-2.12.2 mariadb-100-debugsource-10.0.40.2-2.12.2 - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): libmysqlclient-devel-10.0.40.2-2.12.2 libmysqlclient_r18-10.0.40.2-2.12.2 libmysqld-devel-10.0.40.2-2.12.2 libmysqld18-10.0.40.2-2.12.2 libmysqld18-debuginfo-10.0.40.2-2.12.2 mariadb-100-debuginfo-10.0.40.2-2.12.2 mariadb-100-debugsource-10.0.40.2-2.12.2 - SUSE Linux Enterprise Software Development Kit 12-SP4 (aarch64 ppc64le s390x x86_64): libmysqlclient-devel-10.0.40.2-2.12.2 libmysqlclient_r18-10.0.40.2-2.12.2 libmysqld-devel-10.0.40.2-2.12.2 libmysqld18-10.0.40.2-2.12.2 libmysqld18-debuginfo-10.0.40.2-2.12.2 mariadb-100-debuginfo-10.0.40.2-2.12.2 mariadb-100-debugsource-10.0.40.2-2.12.2 - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): libmysqlclient18-10.0.40.2-2.12.2 libmysqlclient18-debuginfo-10.0.40.2-2.12.2 mariadb-100-debuginfo-10.0.40.2-2.12.2 mariadb-100-debugsource-10.0.40.2-2.12.2 mariadb-100-errormessages-10.0.40.2-2.12.2 - SUSE Linux Enterprise Server 12-SP5 (s390x x86_64): libmysqlclient18-32bit-10.0.40.2-2.12.2 libmysqlclient18-debuginfo-32bit-10.0.40.2-2.12.2 - SUSE Linux Enterprise Server 12-SP4 (aarch64 ppc64le s390x x86_64): libmysqlclient18-10.0.40.2-2.12.2 libmysqlclient18-debuginfo-10.0.40.2-2.12.2 mariadb-100-debuginfo-10.0.40.2-2.12.2 mariadb-100-debugsource-10.0.40.2-2.12.2 mariadb-100-errormessages-10.0.40.2-2.12.2 - SUSE Linux Enterprise Server 12-SP4 (s390x x86_64): libmysqlclient18-32bit-10.0.40.2-2.12.2 libmysqlclient18-debuginfo-32bit-10.0.40.2-2.12.2 - SUSE Linux Enterprise Desktop 12-SP4 (x86_64): libmysqlclient18-10.0.40.2-2.12.2 libmysqlclient18-32bit-10.0.40.2-2.12.2 libmysqlclient18-debuginfo-10.0.40.2-2.12.2 libmysqlclient18-debuginfo-32bit-10.0.40.2-2.12.2 libmysqlclient_r18-10.0.40.2-2.12.2 libmysqlclient_r18-32bit-10.0.40.2-2.12.2 mariadb-100-debuginfo-10.0.40.2-2.12.2 mariadb-100-debugsource-10.0.40.2-2.12.2 mariadb-100-errormessages-10.0.40.2-2.12.2 References: https://www.suse.com/security/cve/CVE-2019-2974.html https://bugzilla.suse.com/1154162 _______________________________________________ sle-security-updates mailing list
Updated mariadb packages fix security vulnerabilities: A vulnerability in Server: Optimizer contains an easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise the server. Successful attacks of this . MGASA-2019-0335 - Updated mariadb packages fix security vulnerabilities Publication date: 19 Nov 2019 URL: https://advisories.mageia.org/MGASA-2019-0335.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-2974, CVE-2019-2938 Updated mariadb packages fix security vulnerabilities: A vulnerability in Server: Optimizer contains an easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise the server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) (CVE-2019-2974). A vulnerability in InnoDB contains an Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise the server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) (CVE-2019-2938). References: - https://bugs.mageia.org/show_bug.cgi?id=25691 - https://www.cve.org/CVERecord?id=CVE-2019-2974 - https://www.cve.org/CVERecord?id=CVE-2019-2938 SRPMS: - 7/core/mariadb-10.3.20-1.mga7 . Updated MariaDB packages resolve Medium security issues as detailed in MGASA-2019-0335. Published on 19 Nov 2019.. updated, mariadb, packages, security, vulnerabilities, vulnerability, server, optimizer. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.