You are here
Home > Preporuke > Sigurnosni nedostaci programskog paketa community-mysql

Sigurnosni nedostaci programskog paketa community-mysql

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LFE

——————————————————————————–
Fedora Update Notification
FEDORA-2019-48a0a07033
2019-11-12 02:08:10.642443
——————————————————————————–

Name : community-mysql
Product : Fedora 30
Version : 8.0.18
Release : 1.fc30
URL : http://www.mysql.com
Summary : MySQL client programs and shared libraries
Description :
MySQL is a multi-user, multi-threaded SQL database server. MySQL is a
client/server implementation consisting of a server daemon (mysqld)
and many different client programs and libraries. The base package
contains the standard MySQL client programs and generic MySQL files.

——————————————————————————–
Update Information:

**MySQL 8.0.18** Release notes:
https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-18.html CVEs fixed:
CVE-2019-2911 CVE-2019-2914 CVE-2019-2938 CVE-2019-2946 CVE-2019-2957
CVE-2019-2960 CVE-2019-2963 CVE-2019-2966 CVE-2019-2967 CVE-2019-2968
CVE-2019-2974 CVE-2019-2982 CVE-2019-2991 CVE-2019-2993 CVE-2019-2997
CVE-2019-2998 CVE-2019-3004 CVE-2019-3009 CVE-2019-3011 CVE-2019-3018
https://bugzilla.redhat.com/show_bug.cgi?id=1768175
https://www.oracle.com/security-alerts/cpuoct2019.html Maintainer notes:
linking with GOLD disabled on armv7hl, because of
https://bugs.mysql.com/bug.php?id=96698
——————————————————————————–
ChangeLog:

* Mon Oct 14 2019 Lars Tangvald <lars.tangvald@oracle.com> – 8.0.18-1
– Update to MySQL 8.0.18
* Mon Aug 19 2019 Michal Schorm <mschorm@redhat.com> – 8.0.17-2
– Use RELRO hardening on all binaries
* Wed Jul 31 2019 Lars Tangvald <lars.tangvald@oracle.com> – 8.0.17-1
– Update to MySQL 8.0.17
* Wed Jul 24 2019 Fedora Release Engineering <releng@fedoraproject.org> – 8.0.16-3
– Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild
* Wed May 1 2019 Michal Schorm <mschorm@redhat.com> – 8.0.16-2
– Remove SysVInit stuff, no longer needed
– Clean up the SPECfile
* Fri Apr 26 2019 Lars Tangvald <lars.tangvald@oracle.com> – 8.0.16-1
– Update to MySQL 8.0.16
– Rediff sharedir patch
– Refresh skip list and use new, required format
– Remove GCC9 patch now upstream
– Upstream: my_safe_process renamed and moved into proper location
– Use upstream option to skip router build
– OpenSSL 1.1.1 and TLSv1.3 is now supported, enable tests
– Update version of bundled Boost
– Start requiring mysql-selinux package
——————————————————————————–
References:

[ 1 ] Bug #1761354 – community-mysql-8.0.18 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1761354
[ 2 ] Bug #1768175 – CVE-2019-2911 CVE-2019-2914 CVE-2019-2938 CVE-2019-2946 CVE-2019-2957 CVE-2019-2960 CVE-2019-2963 CVE-2019-2966 CVE-2019-2967 CVE-2019-2968 CVE-2019-2974 CVE-2019-2982 CVE-2019-2991 CVE-2019-2993 … community-mysql: various flaws [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1768175
——————————————————————————–

This update can be installed with the “dnf” update program. Use
su -c ‘dnf upgrade –advisory FEDORA-2019-48a0a07033’ at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list — package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org

——————————————————————————–
Fedora Update Notification
FEDORA-2019-d40df38271
2019-11-12 02:20:38.843646
——————————————————————————–

Name : community-mysql
Product : Fedora 31
Version : 8.0.18
Release : 1.fc31
URL : http://www.mysql.com
Summary : MySQL client programs and shared libraries
Description :
MySQL is a multi-user, multi-threaded SQL database server. MySQL is a
client/server implementation consisting of a server daemon (mysqld)
and many different client programs and libraries. The base package
contains the standard MySQL client programs and generic MySQL files.

——————————————————————————–
Update Information:

**MySQL 8.0.18** Release notes:
https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-18.html CVEs fixed:
CVE-2019-2911 CVE-2019-2914 CVE-2019-2938 CVE-2019-2946 CVE-2019-2957
CVE-2019-2960 CVE-2019-2963 CVE-2019-2966 CVE-2019-2967 CVE-2019-2968
CVE-2019-2974 CVE-2019-2982 CVE-2019-2991 CVE-2019-2993 CVE-2019-2997
CVE-2019-2998 CVE-2019-3004 CVE-2019-3009 CVE-2019-3011 CVE-2019-3018
https://bugzilla.redhat.com/show_bug.cgi?id=1768175
https://www.oracle.com/security-alerts/cpuoct2019.html Maintainer notes:
linking with GOLD disabled on armv7hl, because of
https://bugs.mysql.com/bug.php?id=96698
——————————————————————————–
ChangeLog:

* Mon Oct 14 2019 Lars Tangvald <lars.tangvald@oracle.com> – 8.0.18-1
– Update to MySQL 8.0.18
——————————————————————————–
References:

[ 1 ] Bug #1761354 – community-mysql-8.0.18 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1761354
[ 2 ] Bug #1768175 – CVE-2019-2911 CVE-2019-2914 CVE-2019-2938 CVE-2019-2946 CVE-2019-2957 CVE-2019-2960 CVE-2019-2963 CVE-2019-2966 CVE-2019-2967 CVE-2019-2968 CVE-2019-2974 CVE-2019-2982 CVE-2019-2991 CVE-2019-2993 … community-mysql: various flaws [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1768175
——————————————————————————–

This update can be installed with the “dnf” update program. Use
su -c ‘dnf upgrade –advisory FEDORA-2019-d40df38271’ at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list — package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org

AutorJosip Papratovic
Cert idNCERT-REF-2019-11-0001-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
IzvorAdobe
Top
More in Preporuke
Sigurnosni nedostaci programskog paketa mupdf

Otkriveni su sigurnosni nedostaci u programskom paketu mupdf za operacijski sustav Fedora. Otkriveni nedostaci potencijalnim napadačima omogućuju izazivanje DoS stanja...

Close