Описание
Security update for mysql
This mysql version update to 5.5.53 fixes the following issues:
- CVE-2016-6662: Unspecified vulnerability in subcomponent Logging (bsc#1005580)
- CVE-2016-7440: Unspecified vulnerability in subcomponent Encryption (bsc#1005581)
- CVE-2016-5584: Unspecified vulnerability in subcomponent Encryption (bsc#1005558)
Release Notes: http://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-53.html
Список пакетов
SUSE Linux Enterprise Server 11 SP4
SUSE Linux Enterprise Server for SAP Applications 11 SP4
SUSE Linux Enterprise Software Development Kit 11 SP4
Ссылки
- Link for SUSE-SU-2016:2780-1
- E-Mail link for SUSE-SU-2016:2780-1
- SUSE Security Ratings
- SUSE Bug 1005558
- SUSE Bug 1005580
- SUSE Bug 1005581
- SUSE CVE CVE-2016-5584 page
- SUSE CVE CVE-2016-6662 page
- SUSE CVE CVE-2016-7440 page
Описание
Unspecified vulnerability in Oracle MySQL 5.5.52 and earlier, 5.6.33 and earlier, and 5.7.15 and earlier allows remote administrators to affect confidentiality via vectors related to Server: Security: Encryption.
Затронутые продукты
Ссылки
- CVE-2016-5584
- SUSE Bug 1005558
- SUSE Bug 1008318
Описание
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x before 5.6.32-78.0, and 5.7.x before 5.7.14-7 allow local users to create arbitrary configurations and bypass certain protection mechanisms by setting general_log_file to a my.cnf configuration. NOTE: this can be leveraged to execute arbitrary code with root privileges by setting malloc_lib. NOTE: the affected MySQL version information is from Oracle's October 2016 CPU. Oracle has not commented on third-party claims that the issue was silently patched in MySQL 5.5.52, 5.6.33, and 5.7.15.
Затронутые продукты
Ссылки
- CVE-2016-6662
- SUSE Bug 1001367
- SUSE Bug 1005580
- SUSE Bug 1020873
- SUSE Bug 1020884
- SUSE Bug 1021755
- SUSE Bug 998309
Описание
The C software implementation of AES Encryption and Decryption in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover AES keys by leveraging cache-bank timing differences.
Затронутые продукты
Ссылки
- CVE-2016-7440
- SUSE Bug 1005581
- SUSE Bug 1008318