Login
Newsletter
Werbung

Sicherheit: Mehrere Probleme in mysql
Aktuelle Meldungen Distributionen
Name: Mehrere Probleme in mysql
ID: FEDORA-2012-0972
Distribution: Fedora
Plattformen: Fedora 16
Datum: Do, 9. Februar 2012, 09:20
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2262
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0075
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0112
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0113
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0114
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0115
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0116
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0117
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0118
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0119
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0120
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0484
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0485
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0486
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0487
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0488
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0489
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0490
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0491
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0492
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0493
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0494
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0495
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0496
Applikationen: MySQL

Originalnachricht

Name        : mysql
Product : Fedora 16
Version : 5.5.20
Release : 1.fc16
URL : http://www.mysql.com
Summary : MySQL client programs and shared libraries
Description :
MySQL is a multi-user, multi-threaded SQL database server. MySQL is a
client/server implementation consisting of a server daemon (mysqld)
and many different client programs and libraries. The base package
contains the standard MySQL client programs and generic MySQL files.

-------------------------------------------------------------------------------
-
Update Information:

- Update to MySQL 5.5.20, for various fixes described at
http://dev.mysql.com/doc/refman/5.5/en/news-5-5-20.html
as well as security fixes described at
http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html

- Re-include the mysqld logrotate script, now that it's not so bogus
-------------------------------------------------------------------------------
-
ChangeLog:

* Fri Jan 27 2012 Tom Lane <tgl@redhat.com> 5.5.20-1
- Update to MySQL 5.5.20, for various fixes described at
http://dev.mysql.com/doc/refman/5.5/en/news-5-5-20.html
as well as security fixes described at
http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html
Resolves: #783828
- Re-include the mysqld logrotate script, now that it's not so bogus
Resolves: #547007
* Wed Jan 4 2012 Tom Lane <tgl@redhat.com> 5.5.19-1
- Update to MySQL 5.5.19, for various fixes described at
http://dev.mysql.com/doc/refman/5.5/en/news-5-5-19.html
* Sun Nov 20 2011 Tom Lane <tgl@redhat.com> 5.5.18-1
- Update to MySQL 5.5.18, for various fixes described at
http://dev.mysql.com/doc/refman/5.5/en/news-5-5-18.html
* Sat Nov 12 2011 Tom Lane <tgl@redhat.com> 5.5.17-1
- Update to MySQL 5.5.17, for various fixes described at
http://dev.mysql.com/doc/refman/5.5/en/news-5-5-17.html
- Get rid of version-number assumption in sysv-to-systemd conversion trigger
* Wed Nov 2 2011 Honza Horak <hhorak@redhat.com> 5.5.16-4
- Don't assume all ethernet devices are named ethX
Resolves: #682365
- Exclude user definition from my.cnf, user is defined in mysqld.service now
Resolves: #661265
* Sun Oct 16 2011 Tom Lane <tgl@redhat.com> 5.5.16-3
- Fix unportable usage associated with va_list arguments
Resolves: #744707
* Sun Oct 16 2011 Tom Lane <tgl@redhat.com> 5.5.16-2
- Update to MySQL 5.5.16, for various fixes described at
http://dev.mysql.com/doc/refman/5.5/en/news-5-5-16.html
* Fri Jul 29 2011 Tom Lane <tgl@redhat.com> 5.5.15-2
- Update to MySQL 5.5.15, for various fixes described at
http://dev.mysql.com/doc/refman/5.5/en/news-5-5-15.html
-------------------------------------------------------------------------------
-
References:

[ 1 ] Bug #783793 - CVE-2011-2262 mysql: Unspecified vulnerability allows
remote attackers to affect availability
https://bugzilla.redhat.com/show_bug.cgi?id=783793
[ 2 ] Bug #783794 - CVE-2012-0075 mysql: Unspecified vulnerability allows
remote authenticated users to affect integrity
https://bugzilla.redhat.com/show_bug.cgi?id=783794
[ 3 ] Bug #783799 - CVE-2012-0112 mysql: Unspecified vulnerability allows
remote authenticated users to affect availability
https://bugzilla.redhat.com/show_bug.cgi?id=783799
[ 4 ] Bug #783800 - CVE-2012-0113 mysql: Unspecified vulnerability allows
remote authenticated users to affect confidentiality and availability
https://bugzilla.redhat.com/show_bug.cgi?id=783800
[ 5 ] Bug #783801 - CVE-2012-0114 mysql: Unspecified vulnerability allows
local users to affect confidentiality and integrity
https://bugzilla.redhat.com/show_bug.cgi?id=783801
[ 6 ] Bug #783802 - CVE-2012-0115 mysql: Unspecified vulnerability allows
remote authenticated users to affect availability
https://bugzilla.redhat.com/show_bug.cgi?id=783802
[ 7 ] Bug #783803 - CVE-2012-0116 mysql: Unspecified vulnerability allows
remote authenticated users to affect confidentiality and integrity
https://bugzilla.redhat.com/show_bug.cgi?id=783803
[ 8 ] Bug #783804 - CVE-2012-0117 mysql: Unspecified vulnerability allows
remote authenticated users to affect availability via unknown vectors
https://bugzilla.redhat.com/show_bug.cgi?id=783804
[ 9 ] Bug #783805 - CVE-2012-0118 mysql: Unspecified vulnerability allows
remote authenticated users to affect confidentiality and availability
https://bugzilla.redhat.com/show_bug.cgi?id=783805
[ 10 ] Bug #783806 - CVE-2012-0119 mysql: Unspecified vulnerability allows
remote authenticated users to affect availability
https://bugzilla.redhat.com/show_bug.cgi?id=783806
[ 11 ] Bug #783807 - CVE-2012-0120 mysql: Unspecified vulnerability allows
remote authenticated users to affect availability
https://bugzilla.redhat.com/show_bug.cgi?id=783807
[ 12 ] Bug #783808 - CVE-2012-0484 mysql: Unspecified vulnerability allows
remote authenticated users to affect confidentiality
https://bugzilla.redhat.com/show_bug.cgi?id=783808
[ 13 ] Bug #783809 - CVE-2012-0485 mysql: Unspecified vulnerability allows
remote authenticated users to affect availability
https://bugzilla.redhat.com/show_bug.cgi?id=783809
[ 14 ] Bug #783810 - CVE-2012-0486 mysql: Unspecified vulnerability allows
remote authenticated users to affect availability via unknown vectors
https://bugzilla.redhat.com/show_bug.cgi?id=783810
[ 15 ] Bug #783812 - CVE-2012-0487 mysql: Unspecified vulnerability allows
remote authenticated users to affect availability via unknown vectors
https://bugzilla.redhat.com/show_bug.cgi?id=783812
[ 16 ] Bug #783813 - CVE-2012-0488 mysql: Unspecified vulnerability allows
remote authenticated users to affect availability via unknown vectors
https://bugzilla.redhat.com/show_bug.cgi?id=783813
[ 17 ] Bug #783814 - CVE-2012-0489 mysql: Unspecified vulnerability allows
remote authenticated users to affect availability via unknown vectors
https://bugzilla.redhat.com/show_bug.cgi?id=783814
[ 18 ] Bug #783815 - CVE-2012-0490 mysql: Unspecified vulnerability allows
remote authenticated users to affect availability
https://bugzilla.redhat.com/show_bug.cgi?id=783815
[ 19 ] Bug #783816 - CVE-2012-0491 mysql: Unspecified vulnerability allows
remote authenticated users to affect availability via unknown vectors
https://bugzilla.redhat.com/show_bug.cgi?id=783816
[ 20 ] Bug #783817 - CVE-2012-0492 mysql: Unspecified vulnerability allows
remote authenticated users to affect availability
https://bugzilla.redhat.com/show_bug.cgi?id=783817
[ 21 ] Bug #783818 - CVE-2012-0493 mysql: Unspecified vulnerability allows
remote authenticated users to affect availability via unknown vectors
https://bugzilla.redhat.com/show_bug.cgi?id=783818
[ 22 ] Bug #783819 - CVE-2012-0494 mysql: Unspecified vulnerability allows
local users to affect availability via unknown vectors
https://bugzilla.redhat.com/show_bug.cgi?id=783819
[ 23 ] Bug #783820 - CVE-2012-0495 mysql: Unspecified vulnerability allows
remote authenticated users to affect availability via unknown vectors
https://bugzilla.redhat.com/show_bug.cgi?id=783820
[ 24 ] Bug #783821 - CVE-2012-0496 mysql: Unspecified vulnerability allows
remote authenticated users to affect confidentiality and integrity via unknown vectors
https://bugzilla.redhat.com/show_bug.cgi?id=783821
-------------------------------------------------------------------------------
-

This update can be installed with the "yum" update program. Use
su -c 'yum update mysql' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
-------------------------------------------------------------------------------
-
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung