Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2016:2395-1

Опубликовано: 27 сент. 2016
Источник: suse-cvrf

Описание

Security update for mariadb

This update for mariadb to 1.0.0.27 fixes the following issues:

Security issue fixed:

Bugs fixed:

  • Make ORDER BY optimization functions take into account multiple equalities. (bsc#949520)

Список пакетов

SUSE Linux Enterprise Server 12-LTSS
libmysqlclient-devel-10.0.27-20.13.1
libmysqlclient18-10.0.27-20.13.1
libmysqlclient18-32bit-10.0.27-20.13.1
libmysqlclient_r18-10.0.27-20.13.1
libmysqld-devel-10.0.27-20.13.1
libmysqld18-10.0.27-20.13.1
mariadb-10.0.27-20.13.1
mariadb-client-10.0.27-20.13.1
mariadb-errormessages-10.0.27-20.13.1
mariadb-tools-10.0.27-20.13.1
SUSE Linux Enterprise Server for SAP Applications 12
libmysqlclient-devel-10.0.27-20.13.1
libmysqlclient18-10.0.27-20.13.1
libmysqlclient18-32bit-10.0.27-20.13.1
libmysqlclient_r18-10.0.27-20.13.1
libmysqld-devel-10.0.27-20.13.1
libmysqld18-10.0.27-20.13.1
mariadb-10.0.27-20.13.1
mariadb-client-10.0.27-20.13.1
mariadb-errormessages-10.0.27-20.13.1
mariadb-tools-10.0.27-20.13.1

Описание

Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x before 5.6.32-78.0, and 5.7.x before 5.7.14-7 allow local users to create arbitrary configurations and bypass certain protection mechanisms by setting general_log_file to a my.cnf configuration. NOTE: this can be leveraged to execute arbitrary code with root privileges by setting malloc_lib. NOTE: the affected MySQL version information is from Oracle's October 2016 CPU. Oracle has not commented on third-party claims that the issue was silently patched in MySQL 5.5.52, 5.6.33, and 5.7.15.


Затронутые продукты
SUSE Linux Enterprise Server 12-LTSS:libmysqlclient-devel-10.0.27-20.13.1
SUSE Linux Enterprise Server 12-LTSS:libmysqlclient18-10.0.27-20.13.1
SUSE Linux Enterprise Server 12-LTSS:libmysqlclient18-32bit-10.0.27-20.13.1
SUSE Linux Enterprise Server 12-LTSS:libmysqlclient_r18-10.0.27-20.13.1

Ссылки