rh-mysql57-mysql-5.7.21-2.el7.1

エラータID: AXSA:2018-2637:01

リリース日: 
2018/03/29 Thursday - 10:43
題名: 
rh-mysql57-mysql-5.7.21-2.el7.1
影響のあるチャネル: 
Asianux Server 7 for x86_64
Severity: 
Moderate
Description: 

MySQL is a multi-user, multi-threaded SQL database server. It consists of the
MySQL server daemon, mysqld, and many client programs.

The following packages have been upgraded to a later upstream version:
rh-mysql57-mysql (5.7.21). (BZ#1533832)

Security Fix(es):

* mysql: sha256_password authentication DoS via long password (CVE-2018-2696)

* mysql: Server: InnoDB unspecified vulnerability (CPU Jan 2018) (CVE-2018-2565)

* mysql: Server: GIS unspecified vulnerability (CPU Jan 2018) (CVE-2018-2573)

* mysql: Server: DML unspecified vulnerability (CPU Jan 2018) (CVE-2018-2576)

* mysql: Stored Procedure unspecified vulnerability (CPU Jan 2018)
(CVE-2018-2583)

* mysql: Server: DML unspecified vulnerability (CPU Jan 2018) (CVE-2018-2586)

* mysql: Server: Performance Schema unspecified vulnerability (CPU Jan 2018)
(CVE-2018-2590)

* mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2018)
(CVE-2018-2600)

* mysql: InnoDB unspecified vulnerability (CPU Jan 2018) (CVE-2018-2612)

* mysql: Server: DDL unspecified vulnerability (CPU Jan 2018) (CVE-2018-2622)

* mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2018)
(CVE-2018-2640)

* mysql: Server: Performance Schema unspecified vulnerability (CPU Jan 2018)
(CVE-2018-2645)

* mysql: Server: DML unspecified vulnerability (CPU Jan 2018) (CVE-2018-2646)

* mysql: Server: Replication unspecified vulnerability (CPU Jan 2018)
(CVE-2018-2647)

* mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2018)
(CVE-2018-2665)

* mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2018)
(CVE-2018-2667)

* mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2018)
(CVE-2018-2668)

* mysql: sha256_password authentication DoS via hash with large rounds value
(CVE-2018-2703)

For more details about the security issue(s), including the impact, a CVSS
score, and other related information, refer to the CVE page(s) listed in the
References section.

The CVE-2018-2696 and CVE-2018-2703 issues were discovered by Asianux Product
Security.

CVE-2018-2565
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
Server: InnoDB). Supported versions that are affected are 5.7.20 and prior.
Easily exploitable vulnerability allows high privileged attacker with network
access via multiple protocols to compromise MySQL Server. Successful attacks of
this vulnerability can result in unauthorized ability to cause a hang or
frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score
4.9 (Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2018-2573
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
Server: GIS). Supported versions that are affected are 5.6.38 and prior and
5.7.20 and prior. Easily exploitable vulnerability allows low privileged
attacker with network access via multiple protocols to compromise MySQL Server.
Successful attacks of this vulnerability can result in unauthorized ability to
cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS
3.0 Base Score 6.5 (Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
CVE-2018-2576
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
Server: DML). Supported versions that are affected are 5.7.20 and prior. Easily
exploitable vulnerability allows high privileged attacker with network access
via multiple protocols to compromise MySQL Server. Successful attacks of this
vulnerability can result in unauthorized ability to cause a hang or frequently
repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9
(Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2018-2583
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
Stored Procedure). Supported versions that are affected are 5.6.38 and prior and
5.7.20 and prior. Easily exploitable vulnerability allows high privileged
attacker with network access via multiple protocols to compromise MySQL Server.
While the vulnerability is in MySQL Server, attacks may significantly impact
additional products. Successful attacks of this vulnerability can result in
unauthorized ability to cause a hang or frequently repeatable crash (complete
DOS) of MySQL Server. CVSS 3.0 Base Score 6.8 (Availability impacts). CVSS
Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H).
CVE-2018-2586
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
Server: DML). Supported versions that are affected are 5.7.20 and prior. Easily
exploitable vulnerability allows high privileged attacker with network access
via multiple protocols to compromise MySQL Server. Successful attacks of this
vulnerability can result in unauthorized ability to cause a hang or frequently
repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9
(Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2018-2590
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
Server: Performance Schema). Supported versions that are affected are 5.6.38 and
prior and 5.7.20 and prior. Easily exploitable vulnerability allows high
privileged attacker with network access via multiple protocols to compromise
MySQL Server. Successful attacks of this vulnerability can result in
unauthorized ability to cause a hang or frequently repeatable crash (complete
DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS
Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2018-2600
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
Server: Optimizer). Supported versions that are affected are 5.7.20 and prior.
Easily exploitable vulnerability allows high privileged attacker with network
access via multiple protocols to compromise MySQL Server. Successful attacks of
this vulnerability can result in unauthorized ability to cause a hang or
frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score
4.9 (Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2018-2612
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
InnoDB). Supported versions that are affected are 5.6.38 and prior and 5.7.20
and prior. Easily exploitable vulnerability allows high privileged attacker with
network access via multiple protocols to compromise MySQL Server. Successful
attacks of this vulnerability can result in unauthorized creation, deletion or
modification access to critical data or all MySQL Server accessible data and
unauthorized ability to cause a hang or frequently repeatable crash (complete
DOS) of MySQL Server. CVSS 3.0 Base Score 6.5 (Integrity and Availability
impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H).
CVE-2018-2622
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
Server: DDL). Supported versions that are affected are 5.5.58 and prior, 5.6.38
and prior and 5.7.20 and prior. Easily exploitable vulnerability allows low
privileged attacker with network access via multiple protocols to compromise
MySQL Server. Successful attacks of this vulnerability can result in
unauthorized ability to cause a hang or frequently repeatable crash (complete
DOS) of MySQL Server. CVSS 3.0 Base Score 6.5 (Availability impacts). CVSS
Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
CVE-2018-2640
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
Server: Optimizer). Supported versions that are affected are 5.5.58 and prior,
5.6.38 and prior and 5.7.20 and prior. Easily exploitable vulnerability allows
low privileged attacker with network access via multiple protocols to compromise
MySQL Server. Successful attacks of this vulnerability can result in
unauthorized ability to cause a hang or frequently repeatable crash (complete
DOS) of MySQL Server. CVSS 3.0 Base Score 6.5 (Availability impacts). CVSS
Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
CVE-2018-2645
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
Server: Performance Schema). Supported versions that are affected are 5.6.38 and
prior and 5.7.20 and prior. Easily exploitable vulnerability allows high
privileged attacker with network access via multiple protocols to compromise
MySQL Server. Successful attacks of this vulnerability can result in
unauthorized access to critical data or complete access to all MySQL Server
accessible data. CVSS 3.0 Base Score 4.9 (Confidentiality impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).
CVE-2018-2646
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
Server: DML). Supported versions that are affected are 5.7.20 and prior. Easily
exploitable vulnerability allows high privileged attacker with network access
via multiple protocols to compromise MySQL Server. Successful attacks of this
vulnerability can result in unauthorized ability to cause a hang or frequently
repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9
(Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2018-2647
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
Server: Replication). Supported versions that are affected are 5.6.38 and prior
and 5.7.20 and prior. Easily exploitable vulnerability allows high privileged
attacker with network access via multiple protocols to compromise MySQL Server.
Successful attacks of this vulnerability can result in unauthorized ability to
cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as
well as unauthorized update, insert or delete access to some of MySQL Server
accessible data. CVSS 3.0 Base Score 5.5 (Integrity and Availability impacts).
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).
CVE-2018-2665
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
Server: Optimizer). Supported versions that are affected are 5.5.58 and prior,
5.6.38 and prior and 5.7.20 and prior. Easily exploitable vulnerability allows
low privileged attacker with network access via multiple protocols to compromise
MySQL Server. Successful attacks of this vulnerability can result in
unauthorized ability to cause a hang or frequently repeatable crash (complete
DOS) of MySQL Server. CVSS 3.0 Base Score 6.5 (Availability impacts). CVSS
Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
CVE-2018-2667
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
Server: Optimizer). Supported versions that are affected are 5.7.20 and prior.
Easily exploitable vulnerability allows high privileged attacker with network
access via multiple protocols to compromise MySQL Server. Successful attacks of
this vulnerability can result in unauthorized ability to cause a hang or
frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score
4.9 (Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2018-2668
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
Server: Optimizer). Supported versions that are affected are 5.5.58 and prior,
5.6.38 and prior and 5.7.20 and prior. Easily exploitable vulnerability allows
low privileged attacker with network access via multiple protocols to compromise
MySQL Server. Successful attacks of this vulnerability can result in
unauthorized ability to cause a hang or frequently repeatable crash (complete
DOS) of MySQL Server. CVSS 3.0 Base Score 6.5 (Availability impacts). CVSS
Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
CVE-2018-2696
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
Server : Security : Privileges). Supported versions that are affected are 5.6.38
and prior and 5.7.20 and prior. Easily exploitable vulnerability allows
unauthenticated attacker with network access via multiple protocols to
compromise MySQL Server. Successful attacks of this vulnerability can result in
unauthorized ability to cause a hang or frequently repeatable crash (complete
DOS) of MySQL Server. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS
Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
CVE-2018-2703
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
Server : Security : Privileges). Supported versions that are affected are 5.6.38
and prior and 5.7.20 and prior. Easily exploitable vulnerability allows low
privileged attacker with network access via multiple protocols to compromise
MySQL Server. Successful attacks of this vulnerability can result in
unauthorized ability to cause a hang or frequently repeatable crash (complete
DOS) of MySQL Server. CVSS 3.0 Base Score 6.5 (Availability impacts). CVSS
Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

解決策: 

Update packages.

追加情報: 

N/A

ダウンロード: 

SRPMS
  1. rh-mysql57-mysql-5.7.21-2.el7.1.src.rpm
    MD5: 9705f630c4fc07fadccd6a9111f535e8
    SHA-256: 63cf714f085e70a2e44fe5db00e15229f194dcf5f4c8bf645958883abfeba49b
    Size: 44.14 MB

Asianux Server 7 for x86_64
  1. rh-mysql57-mysql-5.7.21-2.el7.1.x86_64.rpm
    MD5: d2518be7b62b1105df5d6097002734d2
    SHA-256: 975dc9ae21de8c35087da28aafba3117d6587c3c42700f4a5307fc6848d2fccb
    Size: 8.21 MB
  2. rh-mysql57-mysql-common-5.7.21-2.el7.1.x86_64.rpm
    MD5: 4e3bf0132f5fadcb9861fe7e40f050e0
    SHA-256: b2b198ea4031fcb0baeacaf0cd7a8fb1d84fd5ab87b14055776030833c335d39
    Size: 88.89 kB
  3. rh-mysql57-mysql-config-5.7.21-2.el7.1.x86_64.rpm
    MD5: 8a39da5ee5d63197f6d0177c634bed70
    SHA-256: 5c26514df6f2ad3fd7fef49d7c5aa38de27d48fb836052e4f1049c763cc95e8e
    Size: 60.51 kB
  4. rh-mysql57-mysql-devel-5.7.21-2.el7.1.x86_64.rpm
    MD5: f25ca12b14b4dd5b18520d201adc6adf
    SHA-256: 300e6e92a35408eead7a8b835b82f6ccdbf68eba62d07ad70a4b6b5d478bbb50
    Size: 896.35 kB
  5. rh-mysql57-mysql-errmsg-5.7.21-2.el7.1.x86_64.rpm
    MD5: 0b407677f29c01b5b7a2bad4172602c6
    SHA-256: ca421e877ce5c88ea3dbcae59ab2498e2367661ad5d7efaceb8b65d61bb6b1f7
    Size: 274.44 kB
  6. rh-mysql57-mysql-server-5.7.21-2.el7.1.x86_64.rpm
    MD5: eb96cecfa82d93326e7b4025a1db7aec
    SHA-256: 6327c9c7665429acbdda20cd15ea40959ccffe3aef383da0db216f19ceed8724
    Size: 18.88 MB
  7. rh-mysql57-mysql-test-5.7.21-2.el7.1.x86_64.rpm
    MD5: deb4f5b7b84436561a00e9c53da2672d
    SHA-256: 119b91342bd1266f8908241042c81908295a1077ba27d39be246548b9a06f333
    Size: 15.06 MB