rh-mysql56-mysql-5.6.38-1.el7

エラータID: AXSA:2017-2422:02

Release date: 
Monday, December 4, 2017 - 16:28
Subject: 
rh-mysql56-mysql-5.6.38-1.el7
Affected Channels: 
Asianux Server 7 for x86_64
Severity: 
High
Description: 

MySQL is a multi-user, multi-threaded SQL database server. It consists of the MySQL server daemon, mysqld, and many client programs.

The following packages have been upgraded to a later upstream version: rh-mysql56-mysql (5.6.38). (BZ#1505112)

Security Fix(es):

* This update fixes several vulnerabilities in the MySQL database server. Information about these flaws can be found on the Oracle Critical Patch Update Advisory page listed in the References section. (CVE-2017-10155, CVE-2017-10227, CVE-2017-10268, CVE-2017-10276, CVE-2017-10279, CVE-2017-10283, CVE-2017-10286, CVE-2017-10294, CVE-2017-10314, CVE-2017-10378, CVE-2017-10379, CVE-2017-10384)

CVE-2017-10155
Vulnerability in the MySQL Server component of Oracle MySQL
(subcomponent: Server: Pluggable Auth). Supported versions that are
affected are 5.6.37 and earlier and 5.7.19 and earlier. Easily
exploitable vulnerability allows unauthenticated attacker with network
access via multiple protocols to compromise MySQL Server. Successful
attacks of this vulnerability can result in unauthorized ability to
cause a hang or frequently repeatable crash (complete DOS) of MySQL
Server. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
CVE-2017-10227
Vulnerability in the MySQL Server component of Oracle MySQL
(subcomponent: Server: Optimizer). Supported versions that are
affected are 5.6.37 and earlier and 5.7.19 and earlier. Easily
exploitable vulnerability allows high privileged attacker with network
access via multiple protocols to compromise MySQL Server. Successful
attacks of this vulnerability can result in unauthorized ability to
cause a hang or frequently repeatable crash (complete DOS) of MySQL
Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2017-10268
Vulnerability in the MySQL Server component of Oracle MySQL
(subcomponent: Server: Replication). Supported versions that are
affected are 5.5.57 and earlier, 5.6.37 and earlier and 5.7.19 and
earlier. Difficult to exploit vulnerability allows high privileged
attacker with logon to the infrastructure where MySQL Server executes
to compromise MySQL Server. Successful attacks of this vulnerability
can result in unauthorized access to critical data or complete access
to all MySQL Server accessible data. CVSS 3.0 Base Score 4.1
(Confidentiality impacts). CVSS Vector:
(CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N).
CVE-2017-10276
Vulnerability in the MySQL Server component of Oracle MySQL
(subcomponent: Server: FTS). Supported versions that are affected are
5.6.37 and earlier and 5.7.19 and earlier. Easily exploitable
vulnerability allows low privileged attacker with network access via
multiple protocols to compromise MySQL Server. Successful attacks of
this vulnerability can result in unauthorized ability to cause a hang
or frequently repeatable crash (complete DOS) of MySQL Server. CVSS
3.0 Base Score 6.5 (Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
CVE-2017-10279
Vulnerability in the MySQL Server component of Oracle MySQL
(subcomponent: Server: Optimizer). Supported versions that are
affected are 5.6.36 and earlier and 5.7.18 and earlier. Easily
exploitable vulnerability allows high privileged attacker with network
access via multiple protocols to compromise MySQL Server. Successful
attacks of this vulnerability can result in unauthorized ability to
cause a hang or frequently repeatable crash (complete DOS) of MySQL
Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2017-10283
Vulnerability in the MySQL Server component of Oracle MySQL
(subcomponent: Server: Performance Schema). Supported versions that
are affected are 5.6.37 and earlier and 5.7.19 and earlier. Difficult
to exploit vulnerability allows low privileged attacker with network
access via multiple protocols to compromise MySQL Server. Successful
attacks of this vulnerability can result in unauthorized ability to
cause a hang or frequently repeatable crash (complete DOS) of MySQL
Server. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).
CVE-2017-10286
Vulnerability in the MySQL Server component of Oracle MySQL
(subcomponent: Server: InnoDB). Supported versions that are affected
are 5.6.37 and earlier and 5.7.19 and earlier. Difficult to exploit
vulnerability allows high privileged attacker with network access via
multiple protocols to compromise MySQL Server. Successful attacks of
this vulnerability can result in unauthorized ability to cause a hang
or frequently repeatable crash (complete DOS) of MySQL Server. CVSS
3.0 Base Score 4.4 (Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2017-10294
Vulnerability in the MySQL Server component of Oracle MySQL
(subcomponent: Server: Optimizer). Supported versions that are
affected are 5.6.37 and earlier and 5.7.19 and earlier. Easily
exploitable vulnerability allows high privileged attacker with network
access via multiple protocols to compromise MySQL Server. Successful
attacks of this vulnerability can result in unauthorized ability to
cause a hang or frequently repeatable crash (complete DOS) of MySQL
Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2017-10314
Vulnerability in the MySQL Server component of Oracle MySQL
(subcomponent: Server: Memcached). Supported versions that are
affected are 5.6.37 and earlier and 5.7.19 and earlier. Easily
exploitable vulnerability allows high privileged attacker with network
access via multiple protocols to compromise MySQL Server. Successful
attacks of this vulnerability can result in unauthorized ability to
cause a hang or frequently repeatable crash (complete DOS) of MySQL
Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2017-10378
Vulnerability in the MySQL Server component of Oracle MySQL
(subcomponent: Server: Optimizer). Supported versions that are
affected are 5.5.57 and earlier, 5.6.37 and earlier and 5.7.11 and
earlier. Easily exploitable vulnerability allows low privileged
attacker with network access via multiple protocols to compromise
MySQL Server. Successful attacks of this vulnerability can result in
unauthorized ability to cause a hang or frequently repeatable crash
(complete DOS) of MySQL Server. CVSS 3.0 Base Score 6.5 (Availability
impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
CVE-2017-10379
Vulnerability in the MySQL Server component of Oracle MySQL
(subcomponent: Client programs). Supported versions that are affected
are 5.5.57 and earlier, 5.6.37 and earlier and 5.7.19 and earlier.
Easily exploitable vulnerability allows low privileged attacker with
network access via multiple protocols to compromise MySQL Server.
Successful attacks of this vulnerability can result in unauthorized
access to critical data or complete access to all MySQL Server
accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality impacts).
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
CVE-2017-10384
Vulnerability in the MySQL Server component of Oracle MySQL
(subcomponent: Server: DDL). Supported versions that are affected are
5.5.57 and earlier 5.6.37 and earlier 5.7.19 and earlier. Easily
exploitable vulnerability allows low privileged attacker with network
access via multiple protocols to compromise MySQL Server. Successful
attacks of this vulnerability can result in unauthorized ability to
cause a hang or frequently repeatable crash (complete DOS) of MySQL
Server. CVSS 3.0 Base Score 6.5 (Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. rh-mysql56-mysql-5.6.38-1.el7.src.rpm
    MD5: aff1fd4314d40d813da3c82802f2c5aa
    SHA-256: 612691ecf824a8ef66f25162420ff28bea7e8abead89c0700be537fe43116c4f
    Size: 29.18 MB

Asianux Server 7 for x86_64
  1. rh-mysql56-mysql-5.6.38-1.el7.x86_64.rpm
    MD5: d228c2a8398bd95717a0c12d0fba90e1
    SHA-256: c84af0f07cdcf0f75744d1baccead2dbd212e05c45bc48d21be5821377922959
    Size: 6.59 MB
  2. rh-mysql56-mysql-bench-5.6.38-1.el7.x86_64.rpm
    MD5: 58307f108c8411d05580c0a3dc525fb6
    SHA-256: 0accdf7c3c85328a3fa39a6d7a5eef4725638f6f3ce718321a220298200bc776
    Size: 432.14 kB
  3. rh-mysql56-mysql-common-5.6.38-1.el7.x86_64.rpm
    MD5: 2a0d40d28140ecb08a3002945b7cc870
    SHA-256: f0f61449faf80154302fcf097c54830ed6d11f06f86bfa0943f1f09fe7373349
    Size: 87.82 kB
  4. rh-mysql56-mysql-config-5.6.38-1.el7.x86_64.rpm
    MD5: 0b8ebfca1e763ba8fc4d03d38963d3d0
    SHA-256: 26abd9a3cbd097f4bb8fae6fbe08032045d6d356ff7407c046f93439628b0407
    Size: 59.61 kB
  5. rh-mysql56-mysql-devel-5.6.38-1.el7.x86_64.rpm
    MD5: 98983b768586c7a3f63684c2cb819639
    SHA-256: 5568150c4e716c41e864bd2397a01ff99783aec65760f990a437b439cf08d9ee
    Size: 219.04 kB
  6. rh-mysql56-mysql-errmsg-5.6.38-1.el7.x86_64.rpm
    MD5: 3fe12a1e1345f09b1f5b958beaf847b7
    SHA-256: 28e913f8c01d817dcd03734e5de2bb9fa6365d06514be2dd157e2490e3e5f669
    Size: 259.04 kB
  7. rh-mysql56-mysql-server-5.6.38-1.el7.x86_64.rpm
    MD5: e78e3a1082bf8c4c7c0c69b0438a4ea9
    SHA-256: d783e949962f9e92440af9d978ab73d9e4ce6f7cfe13bab8d457c7719ca566d3
    Size: 11.02 MB
  8. rh-mysql56-mysql-test-5.6.38-1.el7.x86_64.rpm
    MD5: 474911eeafe319c1a52af5cbf6e12b88
    SHA-256: 3c060724350e7d69a759f3d0ab2d63776ef4b31b5108929e64e5428c9d8dca6c
    Size: 9.55 MB