Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2017:1137-1

Опубликовано: 28 апр. 2017
Источник: suse-cvrf

Описание

Security update for mysql

This update for mysql to version 5.5.55 fixes the following issues:

These security issues were fixed:

  • CVE-2017-3308: Unspecified vulnerability in Server: DML (bsc#1034850)
  • CVE-2017-3309: Unspecified vulnerability in Server: Optimizer (bsc#1034850)
  • CVE-2017-3329: Unspecified vulnerability in Server: Thread (bsc#1034850)
  • CVE-2017-3600: Unspecified vulnerability in Client: mysqldump (bsc#1034850)
  • CVE-2017-3453: Unspecified vulnerability in Server: Optimizer (bsc#1034850)
  • CVE-2017-3456: Unspecified vulnerability in Server: DML (bsc#1034850)
  • CVE-2017-3463: Unspecified vulnerability in Server: Security (bsc#1034850)
  • CVE-2017-3462: Unspecified vulnerability in Server: Security (bsc#1034850)
  • CVE-2017-3461: Unspecified vulnerability in Server: Security (bsc#1034850)
  • CVE-2017-3464: Unspecified vulnerability in Server: DDL (bsc#1034850)
  • CVE-2017-3305: MySQL client sent authentication request unencrypted even if SSL was required (aka Ridddle) (bsc#1029396).
  • CVE-2016-5483: Mysqldump failed to properly quote certain identifiers in SQL statements written to the dump output, allowing for execution of arbitrary commands (bsc#1029014)
  • '--ssl-mode=REQUIRED' can be specified to require a secure connection (it fails if a secure connection cannot be obtained)

This non-security issue was fixed:

  • Set the default umask to 077 in rc.mysql-multi [bsc#1020976]

For additional changes please see http://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-55.html

Note: The issue tracked in bsc#1022428 and fixed in the last update was assigned CVE-2017-3302.

Список пакетов

SUSE Linux Enterprise Server 11 SP4
libmysql55client18-5.5.55-0.38.1
libmysql55client18-32bit-5.5.55-0.38.1
libmysql55client18-x86-5.5.55-0.38.1
libmysql55client_r18-5.5.55-0.38.1
libmysql55client_r18-32bit-5.5.55-0.38.1
libmysql55client_r18-x86-5.5.55-0.38.1
mysql-5.5.55-0.38.1
mysql-client-5.5.55-0.38.1
mysql-tools-5.5.55-0.38.1
SUSE Linux Enterprise Server for SAP Applications 11 SP4
libmysql55client18-5.5.55-0.38.1
libmysql55client18-32bit-5.5.55-0.38.1
libmysql55client18-x86-5.5.55-0.38.1
libmysql55client_r18-5.5.55-0.38.1
libmysql55client_r18-32bit-5.5.55-0.38.1
libmysql55client_r18-x86-5.5.55-0.38.1
mysql-5.5.55-0.38.1
mysql-client-5.5.55-0.38.1
mysql-tools-5.5.55-0.38.1
SUSE Linux Enterprise Software Development Kit 11 SP4
libmysql55client_r18-32bit-5.5.55-0.38.1
libmysql55client_r18-x86-5.5.55-0.38.1

Описание

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-3600. Reason: This candidate is a reservation duplicate of CVE-2017-3600. Notes: All CVE users should reference CVE-2017-3600 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:libmysql55client18-32bit-5.5.55-0.38.1
SUSE Linux Enterprise Server 11 SP4:libmysql55client18-5.5.55-0.38.1
SUSE Linux Enterprise Server 11 SP4:libmysql55client18-x86-5.5.55-0.38.1
SUSE Linux Enterprise Server 11 SP4:libmysql55client_r18-32bit-5.5.55-0.38.1

Ссылки

Описание

Crash in libmysqlclient.so in Oracle MySQL before 5.6.21 and 5.7.x before 5.7.5 and MariaDB through 5.5.54, 10.0.x through 10.0.29, 10.1.x through 10.1.21, and 10.2.x through 10.2.3.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:libmysql55client18-32bit-5.5.55-0.38.1
SUSE Linux Enterprise Server 11 SP4:libmysql55client18-5.5.55-0.38.1
SUSE Linux Enterprise Server 11 SP4:libmysql55client18-x86-5.5.55-0.38.1
SUSE Linux Enterprise Server 11 SP4:libmysql55client_r18-32bit-5.5.55-0.38.1

Ссылки

Описание

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: C API). Supported versions that are affected are 5.5.55 and earlier and 5.6.35 and earlier. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Server accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N). NOTE: the previous information is from the April 2017 CPU. Oracle has not commented on third-party claims that this issue allows man-in-the-middle attackers to hijack the authentication of users by leveraging incorrect ordering of security parameter verification in a client, aka, "The Riddle".


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:libmysql55client18-32bit-5.5.55-0.38.1
SUSE Linux Enterprise Server 11 SP4:libmysql55client18-5.5.55-0.38.1
SUSE Linux Enterprise Server 11 SP4:libmysql55client18-x86-5.5.55-0.38.1
SUSE Linux Enterprise Server 11 SP4:libmysql55client_r18-32bit-5.5.55-0.38.1

Ссылки

Описание

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML). Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and 5.7.17 and earlier. Easily "exploitable" vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. While the vulnerability is in MySQL Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 7.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H).


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:libmysql55client18-32bit-5.5.55-0.38.1
SUSE Linux Enterprise Server 11 SP4:libmysql55client18-5.5.55-0.38.1
SUSE Linux Enterprise Server 11 SP4:libmysql55client18-x86-5.5.55-0.38.1
SUSE Linux Enterprise Server 11 SP4:libmysql55client_r18-32bit-5.5.55-0.38.1

Ссылки

Описание

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and 5.7.17 and earlier. Easily "exploitable" vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. While the vulnerability is in MySQL Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 7.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H).


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:libmysql55client18-32bit-5.5.55-0.38.1
SUSE Linux Enterprise Server 11 SP4:libmysql55client18-5.5.55-0.38.1
SUSE Linux Enterprise Server 11 SP4:libmysql55client18-x86-5.5.55-0.38.1
SUSE Linux Enterprise Server 11 SP4:libmysql55client_r18-32bit-5.5.55-0.38.1

Ссылки

Описание

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Thread Pooling). Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and 5.7.17 and earlier. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:libmysql55client18-32bit-5.5.55-0.38.1
SUSE Linux Enterprise Server 11 SP4:libmysql55client18-5.5.55-0.38.1
SUSE Linux Enterprise Server 11 SP4:libmysql55client18-x86-5.5.55-0.38.1
SUSE Linux Enterprise Server 11 SP4:libmysql55client_r18-32bit-5.5.55-0.38.1

Ссылки

Описание

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and 5.7.17 and earlier. Easily "exploitable" vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:libmysql55client18-32bit-5.5.55-0.38.1
SUSE Linux Enterprise Server 11 SP4:libmysql55client18-5.5.55-0.38.1
SUSE Linux Enterprise Server 11 SP4:libmysql55client18-x86-5.5.55-0.38.1
SUSE Linux Enterprise Server 11 SP4:libmysql55client_r18-32bit-5.5.55-0.38.1

Ссылки

Описание

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML). Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and 5.7.17 and earlier. Easily "exploitable" vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:libmysql55client18-32bit-5.5.55-0.38.1
SUSE Linux Enterprise Server 11 SP4:libmysql55client18-5.5.55-0.38.1
SUSE Linux Enterprise Server 11 SP4:libmysql55client18-x86-5.5.55-0.38.1
SUSE Linux Enterprise Server 11 SP4:libmysql55client_r18-32bit-5.5.55-0.38.1

Ссылки

Описание

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and 5.7.17 and earlier. Easily "exploitable" vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:libmysql55client18-32bit-5.5.55-0.38.1
SUSE Linux Enterprise Server 11 SP4:libmysql55client18-5.5.55-0.38.1
SUSE Linux Enterprise Server 11 SP4:libmysql55client18-x86-5.5.55-0.38.1
SUSE Linux Enterprise Server 11 SP4:libmysql55client_r18-32bit-5.5.55-0.38.1

Ссылки

Описание

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and 5.7.17 and earlier. Easily "exploitable" vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:libmysql55client18-32bit-5.5.55-0.38.1
SUSE Linux Enterprise Server 11 SP4:libmysql55client18-5.5.55-0.38.1
SUSE Linux Enterprise Server 11 SP4:libmysql55client18-x86-5.5.55-0.38.1
SUSE Linux Enterprise Server 11 SP4:libmysql55client_r18-32bit-5.5.55-0.38.1

Ссылки

Описание

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and 5.7.17 and earlier. Easily "exploitable" vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:libmysql55client18-32bit-5.5.55-0.38.1
SUSE Linux Enterprise Server 11 SP4:libmysql55client18-5.5.55-0.38.1
SUSE Linux Enterprise Server 11 SP4:libmysql55client18-x86-5.5.55-0.38.1
SUSE Linux Enterprise Server 11 SP4:libmysql55client_r18-32bit-5.5.55-0.38.1

Ссылки

Описание

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and 5.7.17 and earlier. Easily "exploitable" vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.0 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:libmysql55client18-32bit-5.5.55-0.38.1
SUSE Linux Enterprise Server 11 SP4:libmysql55client18-5.5.55-0.38.1
SUSE Linux Enterprise Server 11 SP4:libmysql55client18-x86-5.5.55-0.38.1
SUSE Linux Enterprise Server 11 SP4:libmysql55client_r18-32bit-5.5.55-0.38.1

Ссылки

Описание

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client mysqldump). Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and 5.7.17 and earlier. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in takeover of MySQL Server. Note: CVE-2017-3600 is equivalent to CVE-2016-5483. CVSS 3.0 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:libmysql55client18-32bit-5.5.55-0.38.1
SUSE Linux Enterprise Server 11 SP4:libmysql55client18-5.5.55-0.38.1
SUSE Linux Enterprise Server 11 SP4:libmysql55client18-x86-5.5.55-0.38.1
SUSE Linux Enterprise Server 11 SP4:libmysql55client_r18-32bit-5.5.55-0.38.1

Ссылки
Уязвимость SUSE-SU-2017:1137-1