rh-mysql56-mysql-5.6.38-1.AXS4

エラータID: AXSA:2017-2426:02

Release date: 
Monday, December 4, 2017 - 17:28
Subject: 
rh-mysql56-mysql-5.6.38-1.AXS4
Affected Channels: 
Asianux Server 4 for x86_64
Severity: 
High
Description: 

MySQL is a multi-user, multi-threaded SQL database server. It consists of the MySQL server daemon, mysqld, and many client programs.

The following packages have been upgraded to a later upstream version: rh-mysql56-mysql (5.6.38). (BZ#1505112)

Security Fix(es):

* This update fixes several vulnerabilities in the MySQL database server. Information about these flaws can be found on the Oracle Critical Patch Update Advisory page listed in the References section. (CVE-2017-10155, CVE-2017-10227, CVE-2017-10268, CVE-2017-10276, CVE-2017-10279, CVE-2017-10283, CVE-2017-10286, CVE-2017-10294, CVE-2017-10314, CVE-2017-10378, CVE-2017-10379, CVE-2017-10384)

CVE-2017-10155
Vulnerability in the MySQL Server component of Oracle MySQL
(subcomponent: Server: Pluggable Auth). Supported versions that are
affected are 5.6.37 and earlier and 5.7.19 and earlier. Easily
exploitable vulnerability allows unauthenticated attacker with network
access via multiple protocols to compromise MySQL Server. Successful
attacks of this vulnerability can result in unauthorized ability to
cause a hang or frequently repeatable crash (complete DOS) of MySQL
Server. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
CVE-2017-10227
Vulnerability in the MySQL Server component of Oracle MySQL
(subcomponent: Server: Optimizer). Supported versions that are
affected are 5.6.37 and earlier and 5.7.19 and earlier. Easily
exploitable vulnerability allows high privileged attacker with network
access via multiple protocols to compromise MySQL Server. Successful
attacks of this vulnerability can result in unauthorized ability to
cause a hang or frequently repeatable crash (complete DOS) of MySQL
Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2017-10268
Vulnerability in the MySQL Server component of Oracle MySQL
(subcomponent: Server: Replication). Supported versions that are
affected are 5.5.57 and earlier, 5.6.37 and earlier and 5.7.19 and
earlier. Difficult to exploit vulnerability allows high privileged
attacker with logon to the infrastructure where MySQL Server executes
to compromise MySQL Server. Successful attacks of this vulnerability
can result in unauthorized access to critical data or complete access
to all MySQL Server accessible data. CVSS 3.0 Base Score 4.1
(Confidentiality impacts). CVSS Vector:
(CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N).
CVE-2017-10276
Vulnerability in the MySQL Server component of Oracle MySQL
(subcomponent: Server: FTS). Supported versions that are affected are
5.6.37 and earlier and 5.7.19 and earlier. Easily exploitable
vulnerability allows low privileged attacker with network access via
multiple protocols to compromise MySQL Server. Successful attacks of
this vulnerability can result in unauthorized ability to cause a hang
or frequently repeatable crash (complete DOS) of MySQL Server. CVSS
3.0 Base Score 6.5 (Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
CVE-2017-10279
Vulnerability in the MySQL Server component of Oracle MySQL
(subcomponent: Server: Optimizer). Supported versions that are
affected are 5.6.36 and earlier and 5.7.18 and earlier. Easily
exploitable vulnerability allows high privileged attacker with network
access via multiple protocols to compromise MySQL Server. Successful
attacks of this vulnerability can result in unauthorized ability to
cause a hang or frequently repeatable crash (complete DOS) of MySQL
Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2017-10283
Vulnerability in the MySQL Server component of Oracle MySQL
(subcomponent: Server: Performance Schema). Supported versions that
are affected are 5.6.37 and earlier and 5.7.19 and earlier. Difficult
to exploit vulnerability allows low privileged attacker with network
access via multiple protocols to compromise MySQL Server. Successful
attacks of this vulnerability can result in unauthorized ability to
cause a hang or frequently repeatable crash (complete DOS) of MySQL
Server. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).
CVE-2017-10286
Vulnerability in the MySQL Server component of Oracle MySQL
(subcomponent: Server: InnoDB). Supported versions that are affected
are 5.6.37 and earlier and 5.7.19 and earlier. Difficult to exploit
vulnerability allows high privileged attacker with network access via
multiple protocols to compromise MySQL Server. Successful attacks of
this vulnerability can result in unauthorized ability to cause a hang
or frequently repeatable crash (complete DOS) of MySQL Server. CVSS
3.0 Base Score 4.4 (Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2017-10294
Vulnerability in the MySQL Server component of Oracle MySQL
(subcomponent: Server: Optimizer). Supported versions that are
affected are 5.6.37 and earlier and 5.7.19 and earlier. Easily
exploitable vulnerability allows high privileged attacker with network
access via multiple protocols to compromise MySQL Server. Successful
attacks of this vulnerability can result in unauthorized ability to
cause a hang or frequently repeatable crash (complete DOS) of MySQL
Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2017-10314
Vulnerability in the MySQL Server component of Oracle MySQL
(subcomponent: Server: Memcached). Supported versions that are
affected are 5.6.37 and earlier and 5.7.19 and earlier. Easily
exploitable vulnerability allows high privileged attacker with network
access via multiple protocols to compromise MySQL Server. Successful
attacks of this vulnerability can result in unauthorized ability to
cause a hang or frequently repeatable crash (complete DOS) of MySQL
Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2017-10378
Vulnerability in the MySQL Server component of Oracle MySQL
(subcomponent: Server: Optimizer). Supported versions that are
affected are 5.5.57 and earlier, 5.6.37 and earlier and 5.7.11 and
earlier. Easily exploitable vulnerability allows low privileged
attacker with network access via multiple protocols to compromise
MySQL Server. Successful attacks of this vulnerability can result in
unauthorized ability to cause a hang or frequently repeatable crash
(complete DOS) of MySQL Server. CVSS 3.0 Base Score 6.5 (Availability
impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
CVE-2017-10379
Vulnerability in the MySQL Server component of Oracle MySQL
(subcomponent: Client programs). Supported versions that are affected
are 5.5.57 and earlier, 5.6.37 and earlier and 5.7.19 and earlier.
Easily exploitable vulnerability allows low privileged attacker with
network access via multiple protocols to compromise MySQL Server.
Successful attacks of this vulnerability can result in unauthorized
access to critical data or complete access to all MySQL Server
accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality impacts).
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
CVE-2017-10384
Vulnerability in the MySQL Server component of Oracle MySQL
(subcomponent: Server: DDL). Supported versions that are affected are
5.5.57 and earlier 5.6.37 and earlier 5.7.19 and earlier. Easily
exploitable vulnerability allows low privileged attacker with network
access via multiple protocols to compromise MySQL Server. Successful
attacks of this vulnerability can result in unauthorized ability to
cause a hang or frequently repeatable crash (complete DOS) of MySQL
Server. CVSS 3.0 Base Score 6.5 (Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. rh-mysql56-mysql-5.6.38-1.AXS4.src.rpm
    MD5: 7c889c9665dc2464f15806a097f09154
    SHA-256: 38f49a6953a7ab6e4f9115e7fbdea1bd9519900f3d03a8552d390be91707a182
    Size: 29.18 MB

Asianux Server 4 for x86_64
  1. rh-mysql56-mysql-5.6.38-1.AXS4.x86_64.rpm
    MD5: eac7ab5168a8f72ff8a264431cdb9ec5
    SHA-256: f88aec94e48f1be3dff81e87bb979339ca6f61330dedf8c71910eef6bf8cfe71
    Size: 7.46 MB
  2. rh-mysql56-mysql-bench-5.6.38-1.AXS4.x86_64.rpm
    MD5: cf42fcf51211a5a8a15e51a0c3d0ed3d
    SHA-256: b1aa3723d6da123ed1fd44420844eee7361a8840fb2e2059d33680846be45dba
    Size: 441.73 kB
  3. rh-mysql56-mysql-common-5.6.38-1.AXS4.x86_64.rpm
    MD5: 76f3ba9a80f89b99a01e8a10615c38f4
    SHA-256: c1d49460b4d31ea18efa3615c54f309f400cc0ce49bbd9941f5e051a09659bf2
    Size: 87.30 kB
  4. rh-mysql56-mysql-config-5.6.38-1.AXS4.x86_64.rpm
    MD5: 1cb1f865c7005d1e169f6549f713d30e
    SHA-256: 24581fb796199aa3c5e2c7394d0e3232014bf42f42a2f9fd788b3477c2b04522
    Size: 59.31 kB
  5. rh-mysql56-mysql-devel-5.6.38-1.AXS4.x86_64.rpm
    MD5: ba93f4418f673eb0394dcf3973586630
    SHA-256: d92ee4cdb30ce820e9fbb4e19a96d670526c8d99164754db4df78cd2600ae068
    Size: 218.55 kB
  6. rh-mysql56-mysql-errmsg-5.6.38-1.AXS4.x86_64.rpm
    MD5: 499e5661f2dfe636da8ab16a845886f2
    SHA-256: c8601eda25cc92bb29cb5441eb1417425ec264285e42475f02c7d42a6e3cad21
    Size: 308.84 kB
  7. rh-mysql56-mysql-server-5.6.38-1.AXS4.x86_64.rpm
    MD5: 0ed4023ee27c16a98192744018e036cc
    SHA-256: 465f08bdbee23286e70131219cd4140a8e9ac7e730445b3a6f5f48d09aab0838
    Size: 12.06 MB
  8. rh-mysql56-mysql-test-5.6.38-1.AXS4.x86_64.rpm
    MD5: 4d781c81527b1ec7e2230d3190ec36f8
    SHA-256: c03f6911ef38e4aa89745b628f8b0ecb9332bbf4b7a157e80cfd3a209b70418e
    Size: 10.50 MB