rh-mysql57-mysql-5.7.20-1.el7

エラータID: AXSA:2017-2488:01

Release date: 
Monday, December 25, 2017 - 16:36
Subject: 
rh-mysql57-mysql-5.7.20-1.el7
Affected Channels: 
Asianux Server 7 for x86_64
Severity: 
High
Description: 

MySQL is a multi-user, multi-threaded SQL database server. It consists of the MySQL server daemon, mysqld, and many client programs.

The following packages have been upgraded to a later upstream version: rh-mysql57-mysql (5.7.20). (BZ#1505114)

Security Fix(es):

* This update fixes several vulnerabilities in the MySQL database server. Information about these flaws can be found on the Oracle Critical Patch Update Advisory page listed in the References section. (CVE-2017-10155, CVE-2017-10165, CVE-2017-10167, CVE-2017-10227, CVE-2017-10268, CVE-2017-10276, CVE-2017-10279, CVE-2017-10283, CVE-2017-10284, CVE-2017-10286, CVE-2017-10294, CVE-2017-10296, CVE-2017-10311, CVE-2017-10313, CVE-2017-10314, CVE-2017-10320, CVE-2017-10365, CVE-2017-10378, CVE-2017-10379, CVE-2017-10384)

CVE-2017-10155
Vulnerability in the MySQL Server component of Oracle MySQL
(subcomponent: Server: Pluggable Auth). Supported versions that are
affected are 5.6.37 and earlier and 5.7.19 and earlier. Easily
exploitable vulnerability allows unauthenticated attacker with network
access via multiple protocols to compromise MySQL Server. Successful
attacks of this vulnerability can result in unauthorized ability to
cause a hang or frequently repeatable crash (complete DOS) of MySQL
Server. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
CVE-2017-10165
Vulnerability in the MySQL Server component of Oracle MySQL
(subcomponent: Server: Replication). Supported versions that are
affected are 5.7.19 and earlier. Easily exploitable vulnerability
allows high privileged attacker with network access via multiple
protocols to compromise MySQL Server. Successful attacks of this
vulnerability can result in unauthorized ability to cause a hang or
frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0
Base Score 4.9 (Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2017-10167
Vulnerability in the MySQL Server component of Oracle MySQL
(subcomponent: Server: Optimizer). Supported versions that are
affected are 5.7.19 and earlier. Easily exploitable vulnerability
allows low privileged attacker with network access via multiple
protocols to compromise MySQL Server. Successful attacks of this
vulnerability can result in unauthorized ability to cause a hang or
frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0
Base Score 6.5 (Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
CVE-2017-10227
Vulnerability in the MySQL Server component of Oracle MySQL
(subcomponent: Server: Optimizer). Supported versions that are
affected are 5.6.37 and earlier and 5.7.19 and earlier. Easily
exploitable vulnerability allows high privileged attacker with network
access via multiple protocols to compromise MySQL Server. Successful
attacks of this vulnerability can result in unauthorized ability to
cause a hang or frequently repeatable crash (complete DOS) of MySQL
Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2017-10268
Vulnerability in the MySQL Server component of Oracle MySQL
(subcomponent: Server: Replication). Supported versions that are
affected are 5.5.57 and earlier, 5.6.37 and earlier and 5.7.19 and
earlier. Difficult to exploit vulnerability allows high privileged
attacker with logon to the infrastructure where MySQL Server executes
to compromise MySQL Server. Successful attacks of this vulnerability
can result in unauthorized access to critical data or complete access
to all MySQL Server accessible data. CVSS 3.0 Base Score 4.1
(Confidentiality impacts). CVSS Vector:
(CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N).
CVE-2017-10276
Vulnerability in the MySQL Server component of Oracle MySQL
(subcomponent: Server: FTS). Supported versions that are affected are
5.6.37 and earlier and 5.7.19 and earlier. Easily exploitable
vulnerability allows low privileged attacker with network access via
multiple protocols to compromise MySQL Server. Successful attacks of
this vulnerability can result in unauthorized ability to cause a hang
or frequently repeatable crash (complete DOS) of MySQL Server. CVSS
3.0 Base Score 6.5 (Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
CVE-2017-10279
Vulnerability in the MySQL Server component of Oracle MySQL
(subcomponent: Server: Optimizer). Supported versions that are
affected are 5.6.36 and earlier and 5.7.18 and earlier. Easily
exploitable vulnerability allows high privileged attacker with network
access via multiple protocols to compromise MySQL Server. Successful
attacks of this vulnerability can result in unauthorized ability to
cause a hang or frequently repeatable crash (complete DOS) of MySQL
Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2017-10283
Vulnerability in the MySQL Server component of Oracle MySQL
(subcomponent: Server: Performance Schema). Supported versions that
are affected are 5.6.37 and earlier and 5.7.19 and earlier. Difficult
to exploit vulnerability allows low privileged attacker with network
access via multiple protocols to compromise MySQL Server. Successful
attacks of this vulnerability can result in unauthorized ability to
cause a hang or frequently repeatable crash (complete DOS) of MySQL
Server. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).
CVE-2017-10284
Vulnerability in the MySQL Server component of Oracle MySQL
(subcomponent: Server: Stored Procedure). Supported versions that are
affected are 5.7.18 and earlier. Easily exploitable vulnerability
allows high privileged attacker with network access via multiple
protocols to compromise MySQL Server. Successful attacks of this
vulnerability can result in unauthorized ability to cause a hang or
frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0
Base Score 4.9 (Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2017-10286
Vulnerability in the MySQL Server component of Oracle MySQL
(subcomponent: Server: InnoDB). Supported versions that are affected
are 5.6.37 and earlier and 5.7.19 and earlier. Difficult to exploit
vulnerability allows high privileged attacker with network access via
multiple protocols to compromise MySQL Server. Successful attacks of
this vulnerability can result in unauthorized ability to cause a hang
or frequently repeatable crash (complete DOS) of MySQL Server. CVSS
3.0 Base Score 4.4 (Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2017-10294
Vulnerability in the MySQL Server component of Oracle MySQL
(subcomponent: Server: Optimizer). Supported versions that are
affected are 5.6.37 and earlier and 5.7.19 and earlier. Easily
exploitable vulnerability allows high privileged attacker with network
access via multiple protocols to compromise MySQL Server. Successful
attacks of this vulnerability can result in unauthorized ability to
cause a hang or frequently repeatable crash (complete DOS) of MySQL
Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2017-10296
Vulnerability in the MySQL Server component of Oracle MySQL
(subcomponent: Server: DML). Supported versions that are affected are
5.7.18 and earlier. Easily exploitable vulnerability allows high
privileged attacker with network access via multiple protocols to
compromise MySQL Server. Successful attacks of this vulnerability can
result in unauthorized ability to cause a hang or frequently
repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score
4.9 (Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2017-10311
Vulnerability in the MySQL Server component of Oracle MySQL
(subcomponent: Server: FTS). Supported versions that are affected are
5.7.19 and earlier. Easily exploitable vulnerability allows high
privileged attacker with network access via multiple protocols to
compromise MySQL Server. Successful attacks of this vulnerability can
result in unauthorized ability to cause a hang or frequently
repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score
4.9 (Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2017-10313
Vulnerability in the MySQL Server component of Oracle MySQL
(subcomponent: Group Replication GCS). Supported versions that are
affected are 5.7.19 and earlier. Easily exploitable vulnerability
allows high privileged attacker with network access via multiple
protocols to compromise MySQL Server. Successful attacks of this
vulnerability can result in unauthorized ability to cause a hang or
frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0
Base Score 4.9 (Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2017-10314
Vulnerability in the MySQL Server component of Oracle MySQL
(subcomponent: Server: Memcached). Supported versions that are
affected are 5.6.37 and earlier and 5.7.19 and earlier. Easily
exploitable vulnerability allows high privileged attacker with network
access via multiple protocols to compromise MySQL Server. Successful
attacks of this vulnerability can result in unauthorized ability to
cause a hang or frequently repeatable crash (complete DOS) of MySQL
Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2017-10320
Vulnerability in the MySQL Server component of Oracle MySQL
(subcomponent: Server: InnoDB). Supported versions that are affected
are 5.7.19 and earlier. Easily exploitable vulnerability allows high
privileged attacker with network access via multiple protocols to
compromise MySQL Server. Successful attacks of this vulnerability can
result in unauthorized ability to cause a hang or frequently
repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score
4.9 (Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2017-10365
Vulnerability in the MySQL Server component of Oracle MySQL
(subcomponent: Server: InnoDB). Supported versions that are affected
are 5.7.18 and earlier. Easily exploitable vulnerability allows high
privileged attacker with network access via multiple protocols to
compromise MySQL Server. Successful attacks of this vulnerability can
result in unauthorized update, insert or delete access to some of
MySQL Server accessible data and unauthorized ability to cause a
partial denial of service (partial DOS) of MySQL Server. CVSS 3.0 Base
Score 3.8 (Integrity and Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L).
CVE-2017-10378
Vulnerability in the MySQL Server component of Oracle MySQL
(subcomponent: Server: Optimizer). Supported versions that are
affected are 5.5.57 and earlier, 5.6.37 and earlier and 5.7.11 and
earlier. Easily exploitable vulnerability allows low privileged
attacker with network access via multiple protocols to compromise
MySQL Server. Successful attacks of this vulnerability can result in
unauthorized ability to cause a hang or frequently repeatable crash
(complete DOS) of MySQL Server. CVSS 3.0 Base Score 6.5 (Availability
impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
CVE-2017-10379
Vulnerability in the MySQL Server component of Oracle MySQL
(subcomponent: Client programs). Supported versions that are affected
are 5.5.57 and earlier, 5.6.37 and earlier and 5.7.19 and earlier.
Easily exploitable vulnerability allows low privileged attacker with
network access via multiple protocols to compromise MySQL Server.
Successful attacks of this vulnerability can result in unauthorized
access to critical data or complete access to all MySQL Server
accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality impacts).
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
CVE-2017-10384
Vulnerability in the MySQL Server component of Oracle MySQL
(subcomponent: Server: DDL). Supported versions that are affected are
5.5.57 and earlier 5.6.37 and earlier 5.7.19 and earlier. Easily
exploitable vulnerability allows low privileged attacker with network
access via multiple protocols to compromise MySQL Server. Successful
attacks of this vulnerability can result in unauthorized ability to
cause a hang or frequently repeatable crash (complete DOS) of MySQL
Server. CVSS 3.0 Base Score 6.5 (Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. rh-mysql57-mysql-5.7.20-1.el7.src.rpm
    MD5: d587b1467085027d4616bd59c690864e
    SHA-256: 6a95100ff15568bf5e8c5dfd85b43d70c1b04d7888edbeece9e1814abe668c3a
    Size: 44.04 MB

Asianux Server 7 for x86_64
  1. rh-mysql57-mysql-5.7.20-1.el7.x86_64.rpm
    MD5: 1944395f90410dde13349880cd6b01e3
    SHA-256: cd74728628ae78d9fb07355e5b6e814c928febfda311936023fb4f2c83e826d5
    Size: 8.21 MB
  2. rh-mysql57-mysql-common-5.7.20-1.el7.x86_64.rpm
    MD5: 8b705e6d468745f3a3fe3cf4ba0064a2
    SHA-256: 067c88d3965743a9c09a9bd2da9866fe9a6e0d8b29962a0f3980630c47ee17e9
    Size: 88.09 kB
  3. rh-mysql57-mysql-config-5.7.20-1.el7.x86_64.rpm
    MD5: 594ec74f3cb869c0e40937ce5050f7eb
    SHA-256: ceb4c4658b8af0c67a85379a5f9f08d6179d21946d46b94281de93e9e4843e6b
    Size: 59.71 kB
  4. rh-mysql57-mysql-devel-5.7.20-1.el7.x86_64.rpm
    MD5: 6696436719c235962311ac4217301265
    SHA-256: 46c37c0f9ae6315b1047f96cc6eea76ed3e6ccfd418c4401d3b4dc5a7f154a57
    Size: 894.95 kB
  5. rh-mysql57-mysql-errmsg-5.7.20-1.el7.x86_64.rpm
    MD5: 3b6ddb1252e7e2774f93189136ea7ef8
    SHA-256: f50a42f8be84299cfbba285b617a73719396d9099fb83bc6fa28d48d63912fe9
    Size: 273.32 kB
  6. rh-mysql57-mysql-server-5.7.20-1.el7.x86_64.rpm
    MD5: b7873961e5a4a3c7984a85b2bba17a88
    SHA-256: 65305206e836402f05486fea0d3650648cdb8d75df1f96de70dcf84bdc4e1efa
    Size: 18.86 MB
  7. rh-mysql57-mysql-test-5.7.20-1.el7.x86_64.rpm
    MD5: 4a20e48aea3767ee3e9e9408140ae42f
    SHA-256: de62d1b1f1c510cc179c30d8f05029a268bc8ade750fd2961ad8fccc6788cca0
    Size: 15.02 MB