SUSE-SU-2016:2343-1
Dashboard / Vulnerabilities / SUSE-SU-2016:2343-1
SUSE-SU-2016:2343-1
Summary: Security update for mysql
Details: This mysql update to verson 5.5.52 fixes the following issues: Security issues fixed: - CVE-2016-3477: Fixed unspecified vulnerability in subcomponent parser (bsc#989913). - CVE-2016-3521: Fixed unspecified vulnerability in subcomponent types (bsc#989919). - CVE-2016-3615: Fixed unspecified vulnerability in subcomponent dml (bsc#989922). - CVE-2016-5440: Fixed unspecified vulnerability in subcomponent rbr (bsc#989926). - CVE-2016-6662: A malicious user with SQL and filesystem access could create a my.cnf in the datadir and , under certain circumstances, execute arbitrary code as mysql (or even root) user. (bsc#998309) More details can be found on: http://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-52.html http://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-51.html http://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-50.html Bugs fixed: - bsc#967374: properly restart mysql multi instances during upgrade - bnc#937258: multi script to restart after crash
References: https://www.suse.com/support/update/announcement/2016/suse-su-20162343-1/, https://bugzilla.suse.com/937258, https://bugzilla.suse.com/967374, https://bugzilla.suse.com/989913, https://bugzilla.suse.com/989919, https://bugzilla.suse.com/989922, https://bugzilla.suse.com/989926, https://bugzilla.suse.com/998309, https://www.suse.com/security/cve/CVE-2016-3477, https://www.suse.com/security/cve/CVE-2016-3521, https://www.suse.com/security/cve/CVE-2016-3615, https://www.suse.com/security/cve/CVE-2016-5440, https://www.suse.com/security/cve/CVE-2016-6662
Affected packages
Package
Name: mysql
Purl: pkg:rpm/suse/mysql&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
