Описание
Security update for mariadb
Список пакетов
SUSE Linux Enterprise Desktop 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Workstation Extension 12
Ссылки
- Link for SUSE-SU-2015:1273-1
- E-Mail link for SUSE-SU-2015:1273-1
- SUSE Security Ratings
- SUSE Bug 906574
- SUSE Bug 919053
- SUSE Bug 919062
- SUSE Bug 920865
- SUSE Bug 920896
- SUSE Bug 921333
- SUSE Bug 924663
- SUSE Bug 924960
- SUSE Bug 924961
- SUSE Bug 934789
- SUSE Bug 936407
- SUSE Bug 936408
- SUSE Bug 936409
- SUSE CVE CVE-2014-8964 page
- SUSE CVE CVE-2015-0433 page
- SUSE CVE CVE-2015-0441 page
- SUSE CVE CVE-2015-0499 page
Описание
Heap-based buffer overflow in PCRE 8.36 and earlier allows remote attackers to cause a denial of service (crash) or have other unspecified impact via a crafted regular expression, related to an assertion that allows zero repeats.
Затронутые продукты
Ссылки
- CVE-2014-8964
- SUSE Bug 906574
- SUSE Bug 924960
- SUSE Bug 933288
- SUSE Bug 936408
- SUSE Bug 958373
Описание
Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote authenticated users to affect availability via vectors related to InnoDB : DML.
Затронутые продукты
Ссылки
- CVE-2015-0433
- SUSE Bug 927623
- SUSE Bug 936409
Описание
Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Security : Encryption.
Затронутые продукты
Ссылки
- CVE-2015-0441
- SUSE Bug 927623
- SUSE Bug 936409
Описание
Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Federated.
Затронутые продукты
Ссылки
- CVE-2015-0499
- SUSE Bug 927623
- SUSE Bug 936408
Описание
Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Compiling.
Затронутые продукты
Ссылки
- CVE-2015-0501
- SUSE Bug 927623
- SUSE Bug 936408
Описание
Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect availability via vectors related to DDL.
Затронутые продукты
Ссылки
- CVE-2015-0505
- SUSE Bug 927623
- SUSE Bug 936408
Описание
The compile_branch function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code, cause a denial of service (out-of-bounds heap read and crash), or possibly have other unspecified impact via a regular expression with a group containing a forward reference repeated a large number of times within a repeated outer group that has a zero minimum quantifier.
Затронутые продукты
Ссылки
- CVE-2015-2325
- SUSE Bug 924960
- SUSE Bug 933288
- SUSE Bug 936408
- SUSE Bug 958373
Описание
The pcre_compile2 function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code and cause a denial of service (out-of-bounds read) via regular expression with a group containing both a forward referencing subroutine call and a recursive back reference, as demonstrated by "((?+1)(\1))/".
Затронутые продукты
Ссылки
- CVE-2015-2326
- SUSE Bug 924960
- SUSE Bug 924961
- SUSE Bug 933288
- SUSE Bug 936408
- SUSE Bug 958373
Описание
Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote attackers to affect availability via unknown vectors related to Server : Security : Privileges.
Затронутые продукты
Ссылки
- CVE-2015-2568
- SUSE Bug 927623
- SUSE Bug 936409
Описание
Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Optimizer.
Затронутые продукты
Ссылки
- CVE-2015-2571
- SUSE Bug 927623
- SUSE Bug 936408
Описание
Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote authenticated users to affect availability via vectors related to DDL.
Затронутые продукты
Ссылки
- CVE-2015-2573
- SUSE Bug 927623
- SUSE Bug 936409
Описание
Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, aka a "BACKRONYM" attack.
Затронутые продукты
Ссылки
- CVE-2015-3152
- SUSE Bug 1037590
- SUSE Bug 1047059
- SUSE Bug 1088681
- SUSE Bug 924663
- SUSE Bug 928962
- SUSE Bug 936407