Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2019-2511

Опубликовано: 19 авг. 2019
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2019-2511: mysql:8.0 security update (IMPORTANT)

mecab [0.996-1.9]

  • Release bump for rebuilding on new arches Related: #1518842

[0.996-1.8]

  • skip %verify of /etc/opt/rh/rh-mysql57/mecabrc Resolves: #1382315

[0.996-1.7]

  • Prefix library major number with SCL name in soname

[0.996-1.6]

  • Require runtime package from the scl

[0.996-1.5]

  • Convert to SCL package

[0.996-1.4]

[0.996-1.3]

[0.996-1.2]

  • Rebuilt for GCC 5 C++11 ABI change

[0.996-1.1]

[0.996-1.1]

mecab-ipadic [2.7.0.20070801-16.0.1]

  • Rename the LICENSE.Fedora to LICENSE.oracle

[2.7.0.20070801-16]

  • Rename the LICENSE.fedora to LICENSE.rhel

[2.7.0.20070801-15]

  • Release bump for rebuilding on new arches Related: #1518842

[2.7.0.20070801-14.1]

  • Require runtime package from the scl

[2.7.0.20070801-13.1]

  • Convert to SCL package

[2.7.0.20070801-12.1]

[2.7.0.20070801-11.1]

[2.7.0.20070801-10.1]

[2.7.0.20070801-9.1]

[2.7.0.20070801-8.1]

[2.7.0.20070801-7.1]

[2.7.0.20070801-6.1]

[2.7.0.20070801-5.1]

[2.7.0.20070801-4.1]

  • Fix URL for Source2

[2.7.0.20070801-3]

  • F-12: Mass rebuild

[2.7.0.20070801-2]

  • F-11: Mass rebuild

[2.7.0.20070801.dist.1]

  • License update

[2.7.0.20070801]

  • New release 2.7.0-20070801

[2.7.0.20070610]

  • New release 2.7.0-20070610

[2.7.0.20060707-2]

  • Fix typo

[2.7.0.20060707-1]

  • Initial packaging, based on mecab-jumandic spec file

mysql [8.0.17-3]

  • Use RELRO hardening on all binaries
  • Resolves: #1734420

[8.0.17-2]

  • Use RELRO hardening on all binaries
  • Resolves: #1734420

[8.0.17-1]

  • Rebase to 8.0.17
  • Resolves: #1732042
  • CVEs fixed: CVE-2019-2737 CVE-2019-2738 CVE-2019-2739 CVE-2019-2740 CVE-2019-2741 CVE-2019-2743 CVE-2019-2746 CVE-2019-2747 CVE-2019-2752 CVE-2019-2755 CVE-2019-2757 CVE-2019-2758 CVE-2019-2774 CVE-2019-2778 CVE-2019-2780 CVE-2019-2784 CVE-2019-2785 CVE-2019-2789 CVE-2019-2791 CVE-2019-2795 CVE-2019-2796 CVE-2019-2797 CVE-2019-2798 CVE-2019-2800 CVE-2019-2801 CVE-2019-2802 CVE-2019-2803 CVE-2019-2805 CVE-2019-2808 CVE-2019-2810 CVE-2019-2811 CVE-2019-2812 CVE-2019-2814 CVE-2019-2815 CVE-2019-2819 CVE-2019-2822 CVE-2019-2826 CVE-2019-2830 CVE-2019-2834 CVE-2019-2879

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

Module mysql:8.0 is enabled

mecab

0.996-1.module+el8.0.0+5253+1dce7bb2.9

mecab-ipadic

2.7.0.20070801-16.0.1.module+el8.0.0+5253+1dce7bb2

mecab-ipadic-EUCJP

2.7.0.20070801-16.0.1.module+el8.0.0+5253+1dce7bb2

mysql

8.0.17-3.module+el8.0.0+5253+1dce7bb2

mysql-common

8.0.17-3.module+el8.0.0+5253+1dce7bb2

mysql-devel

8.0.17-3.module+el8.0.0+5253+1dce7bb2

mysql-errmsg

8.0.17-3.module+el8.0.0+5253+1dce7bb2

mysql-libs

8.0.17-3.module+el8.0.0+5253+1dce7bb2

mysql-server

8.0.17-3.module+el8.0.0+5253+1dce7bb2

mysql-test

8.0.17-3.module+el8.0.0+5253+1dce7bb2

Oracle Linux x86_64

Module mysql:8.0 is enabled

mecab

0.996-1.module+el8.0.0+5253+1dce7bb2.9

mecab-ipadic

2.7.0.20070801-16.0.1.module+el8.0.0+5253+1dce7bb2

mecab-ipadic-EUCJP

2.7.0.20070801-16.0.1.module+el8.0.0+5253+1dce7bb2

mysql

8.0.17-3.module+el8.0.0+5253+1dce7bb2

mysql-common

8.0.17-3.module+el8.0.0+5253+1dce7bb2

mysql-devel

8.0.17-3.module+el8.0.0+5253+1dce7bb2

mysql-errmsg

8.0.17-3.module+el8.0.0+5253+1dce7bb2

mysql-libs

8.0.17-3.module+el8.0.0+5253+1dce7bb2

mysql-server

8.0.17-3.module+el8.0.0+5253+1dce7bb2

mysql-test

8.0.17-3.module+el8.0.0+5253+1dce7bb2

Связанные уязвимости

rocky
почти 6 лет назад

Important: mysql:8.0 security update

CVSS3: 4.9
ubuntu
больше 6 лет назад

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
redhat
больше 6 лет назад

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
nvd
больше 6 лет назад

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
debian
больше 6 лет назад

Vulnerability in the MySQL Server component of Oracle MySQL (subcompon ...

Уязвимость ELSA-2019-2511