rh-mysql56-mysql-5.6.30-1.el7

エラータID: AXSA:2016-224:01

リリース日: 
2016/05/02 Monday - 21:09
題名: 
rh-mysql56-mysql-5.6.30-1.el7
影響のあるチャネル: 
Asianux Server 7 for x86_64
Severity: 
High
Description: 

MySQL is a multi-user, multi-threaded SQL database server. MySQL is a
client/server implementation consisting of a server daemon (mysqld)
and many different client programs and libraries. The base package
contains the standard MySQL client programs and generic MySQL files.

Security issues fixed with this release:

CVE-2015-4792
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier
and 5.6.26 and earlier allows remote authenticated users to affect
availability via unknown vectors related to Server : Partition, a
different vulnerability than CVE-2015-4802.
CVE-2015-4800
Unspecified vulnerability in Oracle MySQL Server 5.6.26 and earlier
allows remote authenticated users to affect availability via unknown
vectors related to Server : Optimizer.
CVE-2015-4802
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier
and 5.6.26 and earlier allows remote authenticated users to affect
availability via unknown vectors related to Server : Partition, a
different vulnerability than CVE-2015-4792.
CVE-2015-4815
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier
and 5.6.26 and earlier allows remote authenticated users to affect
availability via vectors related to Server : DDL.
CVE-2015-4826
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier
and 5.6.26 and earlier allows remote authenticated users to affect
confidentiality via unknown vectors related to Server : Types.
CVE-2015-4830
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier
and 5.6.26 and earlier allows remote authenticated users to affect
integrity via unknown vectors related to Server : Security :
Privileges.
CVE-2015-4836
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier,
and 5.6.26 and earlier, allows remote authenticated users to affect
availability via unknown vectors related to Server : SP.
CVE-2015-4858
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier,
and 5.6.26 and earlier, allows remote authenticated users to affect
availability via vectors related to DML, a different vulnerability
than CVE-2015-4913.
CVE-2015-4861
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier,
and 5.6.26 and earlier, allows remote authenticated users to affect
availability via unknown vectors related to Server : InnoDB.
CVE-2015-4862
Unspecified vulnerability in Oracle MySQL Server 5.6.26 and earlier
allows remote authenticated users to affect availability via vectors
related to DML.
CVE-2015-4870
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier,
and 5.6.26 and earlier, allows remote authenticated users to affect
availability via unknown vectors related to Server : Parser.
CVE-2015-4890
Unspecified vulnerability in Oracle MySQL Server 5.6.26 and earlier
allows remote authenticated users to affect availability via unknown
vectors related to Server : Replication.
CVE-2015-4910
Unspecified vulnerability in Oracle MySQL Server 5.6.26 and earlier
allows remote authenticated users to affect availability via unknown
vectors related to Server : Memcached.
CVE-2015-4913
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier
and 5.6.26 and earlier allows remote authenticated users to affect
availability via vectors related to Server : DML, a different
vulnerability than CVE-2015-4858.
CVE-2016-0503
Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9
allows remote authenticated users to affect availability via vectors
related to DML, a different vulnerability than CVE-2016-0504.
CVE-2016-0504
Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9
allows remote authenticated users to affect availability via vectors
related to DML, a different vulnerability than CVE-2016-0503.
CVE-2016-0505
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27
and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before
10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users
to affect availability via unknown vectors related to Options.
CVE-2016-0546
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27
and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before
10.0.23, and 10.1.x before 10.1.10 allows local users to affect
confidentiality, integrity, and availability via unknown vectors
related to Client. NOTE: the previous information is from the January
2016 CPU. Oracle has not commented on third-party claims that these
are multiple buffer overflows in the mysqlshow tool that allow remote
database servers to have unspecified impact via a long table or
database name.
CVE-2016-0595
Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier allows
remote authenticated users to affect availability via vectors related
to DML.
CVE-2016-0596
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier and
5.6.27 and earlier and MariaDB before 5.5.47, 10.0.x before 10.0.23,
and 10.1.x before 10.1.10 allows remote authenticated users to affect
availability via vectors related to DML.
CVE-2016-0597
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27
and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before
10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users
to affect availability via unknown vectors related to Optimizer.
CVE-2016-0598
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27
and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before
10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users
to affect availability via vectors related to DML.
CVE-2016-0600
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27
and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before
10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users
to affect availability via unknown vectors related to InnoDB.
CVE-2016-0605
Unspecified vulnerability in Oracle MySQL 5.6.26 and earlier allows
remote authenticated users to affect availability via unknown vectors.
CVE-2016-0606
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27
and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before
10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users
to affect integrity via unknown vectors related to encryption.
CVE-2016-0607
Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9
allows remote authenticated users to affect availability via unknown
vectors related to replication.
CVE-2016-0608
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27
and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before
10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users
to affect availability via vectors related to UDF.
CVE-2016-0609
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27
and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before
10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users
to affect availability via unknown vectors related to privileges.
CVE-2016-0610
Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and
MariaDB before 10.0.22 and 10.1.x before 10.1.9 allows remote
authenticated users to affect availability via unknown vectors related
to InnoDB.
CVE-2016-0611
Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9
allows remote authenticated users to affect availability via unknown
vectors related to Optimizer.
CVE-2016-0639
Unspecified vulnerability in Oracle MySQL 5.6.29 and earlier and
5.7.11 and earlier allows remote attackers to affect confidentiality,
integrity, and availability via vectors related to Pluggable
Authentication.
CVE-2016-0640
Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28
and earlier, and 5.7.10 and earlier allows local users to affect
integrity and availability via vectors related to DML.
CVE-2016-0641
Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28
and earlier, and 5.7.10 and earlier allows local users to affect
confidentiality and availability via vectors related to MyISAM.
CVE-2016-0642
Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29
and earlier, and 5.7.11 and earlier allows local users to affect
integrity and availability via vectors related to Federated.
CVE-2016-0643
Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29
and earlier, and 5.7.11 and earlier allows local users to affect
confidentiality via vectors related to DML.
CVE-2016-0644
Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28
and earlier, and 5.7.10 and earlier allows local users to affect
availability via vectors related to DDL.
CVE-2016-0646
Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28
and earlier, and 5.7.10 and earlier allows local users to affect
availability via vectors related to DML.
CVE-2016-0647
Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29
and earlier, and 5.7.11 and earlier allows local users to affect
availability via vectors related to FTS.
CVE-2016-0648
Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29
and earlier, and 5.7.11 and earlier allows local users to affect
availability via vectors related to PS.
CVE-2016-0649
Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28
and earlier, and 5.7.10 and earlier allows local users to affect
availability via vectors related to PS.
CVE-2016-0650
Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28
and earlier, and 5.7.10 and earlier allows local users to affect
availability via vectors related to Replication.
CVE-2016-0655
Unspecified vulnerability in Oracle MySQL 5.6.29 and earlier and
5.7.11 and earlier allows local users to affect availability via
vectors related to InnoDB.
CVE-2016-0661
Unspecified vulnerability in Oracle MySQL 5.6.28 and earlier and
5.7.10 and earlier allows local users to affect availability via
vectors related to Options.
CVE-2016-0665
Unspecified vulnerability in Oracle MySQL 5.6.28 and earlier and
5.7.10 and earlier allows local users to affect availability via
vectors related to Security: Encryption.
CVE-2016-0666
Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29
and earlier, and 5.7.11 and earlier allows local users to affect
availability via vectors related to Security: Privileges.
CVE-2016-0668
Unspecified vulnerability in Oracle MySQL 5.6.28 and earlier and
5.7.10 and earlier allows local users to affect availability via
vectors related to InnoDB.
CVE-2016-2047
The ssl_verify_server_cert function in sql-common/client.c in MariaDB
before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10;
Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and
earlier; and Percona Server do not properly verify that the server
hostname matches a domain name in the subject's Common Name (CN) or
subjectAltName field of the X.509 certificate, which allows
man-in-the-middle attackers to spoof SSL servers via a "/CN=" string
in a field in a certificate, as demonstrated by
"/OU=/CN=bar.com/CN=foo.com."

The following packages have been upgraded to a newer upstream version: rh-mysql56-mysql (5.6.30).

解決策: 

Update packages.

追加情報: 

N/A

ダウンロード: 

SRPMS
  1. rh-mysql56-mysql-5.6.30-1.el7.src.rpm
    MD5: 0a1b8765edb29897eab504c6075c8a61
    SHA-256: 1a58875423afb4a1dacfdc8da9b1b73253dbcdc18309fc0c52ed21e8ddecccec
    Size: 29.21 MB

Asianux Server 7 for x86_64
  1. rh-mysql56-mysql-5.6.30-1.el7.x86_64.rpm
    MD5: 3b6fd2a7a6c8de649e2059e17adc8ccf
    SHA-256: 515849e4e4c8883f714e2dcd303d7e3203c5b34becf28b2dd729fab8d0894733
    Size: 6.58 MB
  2. rh-mysql56-mysql-bench-5.6.30-1.el7.x86_64.rpm
    MD5: d3adf028d7deea76b7a0602734630d43
    SHA-256: 76972afa2fc5d660e2c0a34483f0dc64d7b6e004ef637f198b4d16076d985cd3
    Size: 429.45 kB
  3. rh-mysql56-mysql-common-5.6.30-1.el7.x86_64.rpm
    MD5: be3398c157a65c663198b5d8ad894195
    SHA-256: 4afe93887b436dbe3e12a5c3218ecdd593651e8fa50f173d435339c5cffabc9d
    Size: 85.15 kB
  4. rh-mysql56-mysql-config-5.6.30-1.el7.x86_64.rpm
    MD5: 830e496f487c1fbfe1b6e4111a9215dc
    SHA-256: 56e5993d59d68cedb0874fc3880a55ba4a4626d5e452aac0a0c7323ab18334d3
    Size: 56.92 kB
  5. rh-mysql56-mysql-devel-5.6.30-1.el7.x86_64.rpm
    MD5: 52af8d671d4ca96923d30fcc3b17229c
    SHA-256: 75fea96f4735040830949d72afeea53b69267b642a061a26a2a72717a78f0228
    Size: 216.45 kB
  6. rh-mysql56-mysql-errmsg-5.6.30-1.el7.x86_64.rpm
    MD5: 8437836e7e3b096ec85130e6c7055c72
    SHA-256: 2dbb56f8688bb7749efaa962529b2f372634670a5c1ec21185c644df2b02e7ac
    Size: 256.34 kB
  7. rh-mysql56-mysql-server-5.6.30-1.el7.x86_64.rpm
    MD5: 712de009d56b14b1ad2b2b8518008bd9
    SHA-256: 930925a79aa93462db90396d3482d32f8639c0156e5e8314c227edcf3db2398b
    Size: 10.98 MB
  8. rh-mysql56-mysql-test-5.6.30-1.el7.x86_64.rpm
    MD5: 18239d2c2ec25eeddc8da66721bd7d61
    SHA-256: 21c685f5f7579c100f05e5e533c9c0b49daab68b4381b3e494f0dca3c0f23203
    Size: 9.49 MB