You are here
Home > Preporuke > Nadogradnja za MySQL

Nadogradnja za MySQL

  • Detalji os-a: LUB
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LUB

==========================================================================
Ubuntu Security Notice USN-2781-1
October 26, 2015

mysql-5.5, mysql-5.6 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 15.10
– Ubuntu 15.04
– Ubuntu 14.04 LTS
– Ubuntu 12.04 LTS

Summary:

Several security issues were fixed in MySQL.

Software Description:
– mysql-5.6: MySQL database
– mysql-5.5: MySQL database

Details:

Multiple security issues were discovered in MySQL and this update includes
new upstream MySQL versions to fix these issues.

MySQL has been updated to 5.5.46 in Ubuntu 12.04 LTS and Ubuntu 14.04 LTS.
Ubuntu 15.04 and Ubuntu 15.10 have been updated to MySQL 5.6.27.

In addition to security fixes, the updated packages contain bug fixes,
new features, and possibly incompatible changes.

Please see the following for more information:
http://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-45.html
http://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-46.html
http://dev.mysql.com/doc/relnotes/mysql/5.6/en/news-5-6-26.html
http://dev.mysql.com/doc/relnotes/mysql/5.6/en/news-5-6-27.html
http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
mysql-server-5.6 5.6.27-0ubuntu1

Ubuntu 15.04:
mysql-server-5.6 5.6.27-0ubuntu0.15.04.1

Ubuntu 14.04 LTS:
mysql-server-5.5 5.5.46-0ubuntu0.14.04.2

Ubuntu 12.04 LTS:
mysql-server-5.5 5.5.46-0ubuntu0.12.04.2

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2781-1
CVE-2015-4730, CVE-2015-4766, CVE-2015-4792, CVE-2015-4800,
CVE-2015-4802, CVE-2015-4815, CVE-2015-4816, CVE-2015-4819,
CVE-2015-4826, CVE-2015-4830, CVE-2015-4833, CVE-2015-4836,
CVE-2015-4858, CVE-2015-4861, CVE-2015-4862, CVE-2015-4864,
CVE-2015-4866, CVE-2015-4870, CVE-2015-4879, CVE-2015-4890,
CVE-2015-4895, CVE-2015-4904, CVE-2015-4910, CVE-2015-4913

Package Information:
https://launchpad.net/ubuntu/+source/mysql-5.6/5.6.27-0ubuntu1
https://launchpad.net/ubuntu/+source/mysql-5.6/5.6.27-0ubuntu0.15.04.1
https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.46-0ubuntu0.14.04.2
https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.46-0ubuntu0.12.04.2

—–BEGIN PGP SIGNATURE—–
Version: GnuPG v2

iQIcBAEBCgAGBQJWLkPxAAoJEGVp2FWnRL6TE0AQAKPYUsKwbroj7LUqeXuo/E1s
0hq4kAQa35BFB3enzjVradeFj/VgnmY0FBRu3jhTqv59chb1Wyy0FO5WcpGeqBZX
A0KYKj+XUxsmD9crVNzHPV1AvuSOrGYEAaS/zIpzexIjZyYPBHWaonPGWmac4YrZ
qobKMjkXAJ1Qr4XgclUemqwgzh3q+XafCgoRg98zU7KwUe/3c8zF8x7FXIhpX3Am
ofJhuoQ+RWs8quJwB+uCD9tldaJd9FVs86XA7IOxktWOYNhlmahoK3o/3YrwDFx5
0JyzAu2TIcntXdTaF/cqjGtknpDaw7R2rohi5qqI5MhBBnEo5BIWXA6+FKYelG+z
mtw4+gI3kiwAqX+M1XKpARvAulPznWqiSfvLV1rsRbEtYXJBYEAJ6emYcZxvF0eh
dYxbV6bSo3+2BhRVrqivFFVG/cRXDD9HSApNao8xKKTIZOWQTHqT/HWV5+Zurbk9
wifpuvB26JdZsRHaO9iUsAKU2raMKhJ/Prl52ipQV7J1Bm+aMP19hOnAx2i08s8A
7zVeuwYe2DlFgXQcosJ1+0ywdw36SAR4LKJrDjq9xmiMYpAScoxkODxHlaSUgyS9
0/dD4mPGfC2GRmEYBUfnhUim5HVtr/up1g9yPRfbG13p+vNhvZkTJByRv0s9b0+9
ObcwM9RFyaYDJMsizgdZ
=HPmm
—–END PGP SIGNATURE—–

AutorTomislav Protega
Cert idNCERT-REF-2015-10-0005-ADV
CveCVE-2010-2883 CVE-2010-2884 CVE-2010-2887 CVE-2010-2888
ID izvornikaUSN-2781-1
Proizvodmysql-5.5, mysql-5.6
Izvorhttp://www.ubuntu.com
Top
More in Preporuke
Sigurnosni nedostaci programskog paketa mysql-5.5

Otkriveni su sigurnosni nedostaci u programskom paketu mysql-5.5. Otkriveni nedostaci lokalnim i udaljenim autenticiranim napadačima omogućuju utjecaj na povjerljivost, dostupnost...

Close