Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2015:1788-1

Опубликовано: 22 сент. 2015
Источник: suse-cvrf

Описание

Security update for mysql

MySQL was updated to version 5.5.45, fixing bugs and security issues.

A list of all changes can be found on:

To fix the 'BACKRONYM' security issue (CVE-2015-3152) the behaviour of the SSL options was changed slightly to meet expectations: Now using '--ssl-verify-server-cert' and '--ssl[-*]' implies that the ssl connection is required. The mysql client will now print an error if ssl is required, but the server can not handle a ssl connection [bnc#924663], [bnc#928962], [CVE-2015-3152]

Additional bugs fixed:

  • fix rc.mysql-multi script to start instances after restart properly [bnc#934401].

Список пакетов

SUSE Linux Enterprise Desktop 11 SP3
libmysql55client18-5.5.45-0.11.1
libmysql55client18-32bit-5.5.45-0.11.1
libmysql55client_r18-5.5.45-0.11.1
libmysql55client_r18-32bit-5.5.45-0.11.1
mysql-5.5.45-0.11.1
mysql-client-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP4
libmysql55client18-5.5.45-0.11.1
libmysql55client18-32bit-5.5.45-0.11.1
libmysql55client_r18-5.5.45-0.11.1
libmysql55client_r18-32bit-5.5.45-0.11.1
mysql-5.5.45-0.11.1
mysql-client-5.5.45-0.11.1
SUSE Linux Enterprise Server 11 SP3
libmysql55client18-5.5.45-0.11.1
libmysql55client18-32bit-5.5.45-0.11.1
libmysql55client18-x86-5.5.45-0.11.1
libmysql55client_r18-5.5.45-0.11.1
mysql-5.5.45-0.11.1
mysql-client-5.5.45-0.11.1
mysql-tools-5.5.45-0.11.1
SUSE Linux Enterprise Server 11 SP3-TERADATA
libmysql55client18-5.5.45-0.11.1
libmysql55client18-32bit-5.5.45-0.11.1
libmysql55client18-x86-5.5.45-0.11.1
libmysql55client_r18-5.5.45-0.11.1
mysql-5.5.45-0.11.1
mysql-client-5.5.45-0.11.1
mysql-tools-5.5.45-0.11.1
SUSE Linux Enterprise Server 11 SP4
libmysql55client18-5.5.45-0.11.1
libmysql55client18-32bit-5.5.45-0.11.1
libmysql55client18-x86-5.5.45-0.11.1
libmysql55client_r18-5.5.45-0.11.1
libmysql55client_r18-32bit-5.5.45-0.11.1
libmysql55client_r18-x86-5.5.45-0.11.1
mysql-5.5.45-0.11.1
mysql-client-5.5.45-0.11.1
mysql-tools-5.5.45-0.11.1
SUSE Linux Enterprise Server for SAP Applications 11 SP3
libmysql55client18-5.5.45-0.11.1
libmysql55client18-32bit-5.5.45-0.11.1
libmysql55client18-x86-5.5.45-0.11.1
libmysql55client_r18-5.5.45-0.11.1
mysql-5.5.45-0.11.1
mysql-client-5.5.45-0.11.1
mysql-tools-5.5.45-0.11.1
SUSE Linux Enterprise Server for SAP Applications 11 SP4
libmysql55client18-5.5.45-0.11.1
libmysql55client18-32bit-5.5.45-0.11.1
libmysql55client18-x86-5.5.45-0.11.1
libmysql55client_r18-5.5.45-0.11.1
libmysql55client_r18-32bit-5.5.45-0.11.1
libmysql55client_r18-x86-5.5.45-0.11.1
mysql-5.5.45-0.11.1
mysql-client-5.5.45-0.11.1
mysql-tools-5.5.45-0.11.1
SUSE Linux Enterprise Software Development Kit 11 SP3
libmysql55client_r18-32bit-5.5.45-0.11.1
libmysql55client_r18-x86-5.5.45-0.11.1
SUSE Linux Enterprise Software Development Kit 11 SP4
libmysql55client_r18-32bit-5.5.45-0.11.1
libmysql55client_r18-x86-5.5.45-0.11.1

Описание

Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows remote authenticated users to affect availability via vectors related to GIS.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client18-32bit-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client18-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client_r18-32bit-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client_r18-5.5.45-0.11.1

Ссылки

Описание

Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect availability via vectors related to DML.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client18-32bit-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client18-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client_r18-32bit-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client_r18-5.5.45-0.11.1

Ссылки

Описание

Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Partition.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client18-32bit-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client18-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client_r18-32bit-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client_r18-5.5.45-0.11.1

Ссылки

Описание

Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.23 and earlier allows remote authenticated users to affect confidentiality via unknown vectors related to Server : Security : Privileges.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client18-32bit-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client18-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client_r18-32bit-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client_r18-5.5.45-0.11.1

Ссылки

Описание

Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Server : Security : Firewall.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client18-32bit-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client18-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client_r18-32bit-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client_r18-5.5.45-0.11.1

Ссылки

Описание

Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Security : Privileges.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client18-32bit-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client18-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client_r18-32bit-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client_r18-5.5.45-0.11.1

Ссылки

Описание

Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Optimizer.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client18-32bit-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client18-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client_r18-32bit-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client_r18-5.5.45-0.11.1

Ссылки

Описание

Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows remote authenticated users to affect availability via vectors related to DML.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client18-32bit-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client18-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client_r18-32bit-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client_r18-5.5.45-0.11.1

Ссылки

Описание

Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows local users to affect availability via unknown vectors related to Client.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client18-32bit-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client18-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client_r18-32bit-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client_r18-5.5.45-0.11.1

Ссылки

Описание

Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, aka a "BACKRONYM" attack.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client18-32bit-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client18-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client_r18-32bit-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client_r18-5.5.45-0.11.1

Ссылки

Описание

Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect confidentiality via unknown vectors related to Server : Pluggable Auth.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client18-32bit-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client18-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client_r18-32bit-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client_r18-5.5.45-0.11.1

Ссылки

Описание

Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows remote authenticated users to affect availability via vectors related to Server : I_S.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client18-32bit-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client18-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client_r18-32bit-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client_r18-5.5.45-0.11.1

Ссылки

Описание

Unspecified vulnerability in Oracle MySQL Server 5.6.22 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : InnoDB, a different vulnerability than CVE-2015-0439.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client18-32bit-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client18-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client_r18-32bit-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client_r18-5.5.45-0.11.1

Ссылки

Описание

Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier and 5.6.23 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Optimizer.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client18-32bit-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client18-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client_r18-32bit-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client_r18-5.5.45-0.11.1

Ссылки

Описание

Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Memcached.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client18-32bit-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client18-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client_r18-32bit-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client_r18-5.5.45-0.11.1

Ссылки

Описание

Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Security : Firewall, a different vulnerability than CVE-2015-4769.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client18-32bit-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client18-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client_r18-32bit-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client_r18-5.5.45-0.11.1

Ссылки

Описание

Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Security : Firewall, a different vulnerability than CVE-2015-4767.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client18-32bit-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client18-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client_r18-32bit-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client_r18-5.5.45-0.11.1

Ссылки

Описание

Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect availability via vectors related to RBR.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client18-32bit-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client18-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client_r18-32bit-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client_r18-5.5.45-0.11.1

Ссылки

Описание

Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Partition.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client18-32bit-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client18-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client_r18-32bit-5.5.45-0.11.1
SUSE Linux Enterprise Desktop 11 SP3:libmysql55client_r18-5.5.45-0.11.1

Ссылки
Уязвимость SUSE-SU-2015:1788-1