You are here
Home > Preporuke > Sigurnosni nedostaci programskih paketa mysql-5.5 i mysql-5.7

Sigurnosni nedostaci programskih paketa mysql-5.5 i mysql-5.7

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LUB

==========================================================================
Ubuntu Security Notice USN-3459-1
October 23, 2017

mysql-5.5, mysql-5.7 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 17.10
– Ubuntu 17.04
– Ubuntu 16.04 LTS
– Ubuntu 14.04 LTS

Summary:

Several security issues were fixed in MySQL.

Software Description:
– mysql-5.7: MySQL database
– mysql-5.5: MySQL database

Details:

Multiple security issues were discovered in MySQL and this update includes
new upstream MySQL versions to fix these issues.

MySQL has been updated to 5.5.58 in Ubuntu 14.04 LTS. Ubuntu 16.04 LTS,
Ubuntu 17.04 and Ubuntu 17.10 have been updated to MySQL 5.7.20.

In addition to security fixes, the updated packages contain bug fixes,
new features, and possibly incompatible changes.

Please see the following for more information:
http://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-58.html
http://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-20.html
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 17.10:
mysql-server-5.7 5.7.20-0ubuntu0.17.10.1

Ubuntu 17.04:
mysql-server-5.7 5.7.20-0ubuntu0.17.04.1

Ubuntu 16.04 LTS:
mysql-server-5.7 5.7.20-0ubuntu0.16.04.1

Ubuntu 14.04 LTS:
mysql-server-5.5 5.5.58-0ubuntu0.14.04.1

In general, a standard system update will make all the necessary changes.

References:
https://www.ubuntu.com/usn/usn-3459-1
CVE-2017-10155, CVE-2017-10165, CVE-2017-10167, CVE-2017-10227,
CVE-2017-10268, CVE-2017-10276, CVE-2017-10283, CVE-2017-10286,
CVE-2017-10294, CVE-2017-10311, CVE-2017-10313, CVE-2017-10314,
CVE-2017-10320, CVE-2017-10378, CVE-2017-10379, CVE-2017-10384

Package Information:
https://launchpad.net/ubuntu/+source/mysql-5.7/5.7.20-0ubuntu0.17.10.1
https://launchpad.net/ubuntu/+source/mysql-5.7/5.7.20-0ubuntu0.17.04.1
https://launchpad.net/ubuntu/+source/mysql-5.7/5.7.20-0ubuntu0.16.04.1
https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.58-0ubuntu0.14.04.1

—–BEGIN PGP SIGNATURE—–
Version: GnuPG v2

iQIcBAEBCgAGBQJZ7e0EAAoJEGVp2FWnRL6TTbIQALuaf9sT2PRjLljsOJQeXeD1
KrlVXW1w2qt3rV0vaUNY59Bu5Idu+NnTHqxuUXZls28ql3nvLkPqyHZPW7X3xeqX
WKINWIiDFHLqI6vOjkdHqrwepf56GzP+YGGWF71rkQQyfDcy5ktDWlJJpAb74/o0
Nmzn+pc4ye9e+FGPuboOYCV0ZSUTtGRhmyoGwV8JwJ30mntE8J7XTsVBbGfrv9Mm
oTXaPO0Mr99+3AMwZTWGFyDyeIx5beFxaA2V6tUo+KJ8Jh5si20DTQ9kvKphAuDg
fHXSmu+aAwUkX2XPneYqcLATMN8cXzbRhEjS+DqMfOUHf7peIISCtK/yDcKo64RU
CEjIl4ECgrAAnGydeYEAW2+eWvwfRuQuF5p2fIw4vEN3rgUyRvsMPc4C0zi01sH3
S8jZcS71hP7BEvQj3RdV4suPcNQiAvQtKgGXYE9LcVgB8/Gm4AI3dTYB4ancxifp
0pqAllRoMpFYgoNRBuSenhMT8UAoSASiB8GlKwic92l3BHXyB1qNgm0VpvV+SNKr
kWf7AQl4qMluh1qbVrm4GYDWGsGtbVCpkZCKoYZhz0wS60/E11ZqVx0HgvAPvKoi
tBS6Xj1utwAS2UPVFkUgwZJEvDKD6VZn3TB7rIDnhwxvgCy+7aNuWIYY6+swrW7M
zABoi09Mzjqj1BnMIcnp
=aA0i
—–END PGP SIGNATURE—–

AutorDanijel Kozinovic
Cert idNCERT-REF-2017-10-0018-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
Izvorhttp://www.adobe.com/
Top
More in Preporuke
Sigurnosni nedostaci programskog paketa curl

Otkriveni su sigurnosni nedostaci u programskom paketu curl za operacijski sustav Ubuntu 12.04 ESM. Otkriveni nedostaci potencijalnim napadačima omogućuju izvođenje...

Close