rh-mysql56-mysql-5.6.39-1.AXS4.1

エラータID: AXSA:2018-2638:01

リリース日: 
2018/03/29 Thursday - 11:14
題名: 
rh-mysql56-mysql-5.6.39-1.AXS4.1
影響のあるチャネル: 
Asianux Server 4 for x86_64
Severity: 
Moderate
Description: 

MySQL is a multi-user, multi-threaded SQL database server. It consists of the
MySQL server daemon, mysqld, and many client programs.

The following packages have been upgraded to a later upstream version:
rh-mysql56-mysql (5.6.39). (BZ#1533831)

Security Fix(es):

* mysql: sha256_password authentication DoS via long password (CVE-2018-2696)

* mysql: Server : Partition unspecified vulnerability (CPU Jan 2018)
(CVE-2018-2562)

* mysql: Server: GIS unspecified vulnerability (CPU Jan 2018) (CVE-2018-2573)

* mysql: Stored Procedure unspecified vulnerability (CPU Jan 2018)
(CVE-2018-2583)

* mysql: Server: Performance Schema unspecified vulnerability (CPU Jan 2018)
(CVE-2018-2590)

* mysql: Server : Partition unspecified vulnerability (CPU Jan 2018)
(CVE-2018-2591)

* mysql: InnoDB unspecified vulnerability (CPU Jan 2018) (CVE-2018-2612)

* mysql: Server: DDL unspecified vulnerability (CPU Jan 2018) (CVE-2018-2622)

* mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2018)
(CVE-2018-2640)

* mysql: Server: Performance Schema unspecified vulnerability (CPU Jan 2018)
(CVE-2018-2645)

* mysql: Server: Replication unspecified vulnerability (CPU Jan 2018)
(CVE-2018-2647)

* mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2018)
(CVE-2018-2665)

* mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2018)
(CVE-2018-2668)

* mysql: sha256_password authentication DoS via hash with large rounds value
(CVE-2018-2703)

For more details about the security issue(s), including the impact, a CVSS
score, and other related information, refer to the CVE page(s) listed in the
References section.

The CVE-2018-2696 and CVE-2018-2703 issues were discovered by Asianux Product
Security.

CVE-2018-2562
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
Server : Partition). Supported versions that are affected are 5.5.58 and prior,
5.6.38 and prior and 5.7.19 and prior. Easily exploitable vulnerability allows
low privileged attacker with network access via multiple protocols to compromise
MySQL Server. Successful attacks of this vulnerability can result in
unauthorized ability to cause a hang or frequently repeatable crash (complete
DOS) of MySQL Server as well as unauthorized update, insert or delete access to
some of MySQL Server accessible data. CVSS 3.0 Base Score 7.1 (Integrity and
Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H).
CVE-2018-2573
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
Server: GIS). Supported versions that are affected are 5.6.38 and prior and
5.7.20 and prior. Easily exploitable vulnerability allows low privileged
attacker with network access via multiple protocols to compromise MySQL Server.
Successful attacks of this vulnerability can result in unauthorized ability to
cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS
3.0 Base Score 6.5 (Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
CVE-2018-2583
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
Stored Procedure). Supported versions that are affected are 5.6.38 and prior and
5.7.20 and prior. Easily exploitable vulnerability allows high privileged
attacker with network access via multiple protocols to compromise MySQL Server.
While the vulnerability is in MySQL Server, attacks may significantly impact
additional products. Successful attacks of this vulnerability can result in
unauthorized ability to cause a hang or frequently repeatable crash (complete
DOS) of MySQL Server. CVSS 3.0 Base Score 6.8 (Availability impacts). CVSS
Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H).
CVE-2018-2590
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
Server: Performance Schema). Supported versions that are affected are 5.6.38 and
prior and 5.7.20 and prior. Easily exploitable vulnerability allows high
privileged attacker with network access via multiple protocols to compromise
MySQL Server. Successful attacks of this vulnerability can result in
unauthorized ability to cause a hang or frequently repeatable crash (complete
DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS
Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2018-2591
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
Server : Partition). Supported versions that are affected are 5.6.38 and prior
and 5.7.19 and prior. Easily exploitable vulnerability allows high privileged
attacker with network access via multiple protocols to compromise MySQL Server.
Successful attacks of this vulnerability can result in unauthorized ability to
cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS
3.0 Base Score 4.9 (Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2018-2612
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
InnoDB). Supported versions that are affected are 5.6.38 and prior and 5.7.20
and prior. Easily exploitable vulnerability allows high privileged attacker with
network access via multiple protocols to compromise MySQL Server. Successful
attacks of this vulnerability can result in unauthorized creation, deletion or
modification access to critical data or all MySQL Server accessible data and
unauthorized ability to cause a hang or frequently repeatable crash (complete
DOS) of MySQL Server. CVSS 3.0 Base Score 6.5 (Integrity and Availability
impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H).
CVE-2018-2622
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
Server: DDL). Supported versions that are affected are 5.5.58 and prior, 5.6.38
and prior and 5.7.20 and prior. Easily exploitable vulnerability allows low
privileged attacker with network access via multiple protocols to compromise
MySQL Server. Successful attacks of this vulnerability can result in
unauthorized ability to cause a hang or frequently repeatable crash (complete
DOS) of MySQL Server. CVSS 3.0 Base Score 6.5 (Availability impacts). CVSS
Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
CVE-2018-2640
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
Server: Optimizer). Supported versions that are affected are 5.5.58 and prior,
5.6.38 and prior and 5.7.20 and prior. Easily exploitable vulnerability allows
low privileged attacker with network access via multiple protocols to compromise
MySQL Server. Successful attacks of this vulnerability can result in
unauthorized ability to cause a hang or frequently repeatable crash (complete
DOS) of MySQL Server. CVSS 3.0 Base Score 6.5 (Availability impacts). CVSS
Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
CVE-2018-2645
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
Server: Performance Schema). Supported versions that are affected are 5.6.38 and
prior and 5.7.20 and prior. Easily exploitable vulnerability allows high
privileged attacker with network access via multiple protocols to compromise
MySQL Server. Successful attacks of this vulnerability can result in
unauthorized access to critical data or complete access to all MySQL Server
accessible data. CVSS 3.0 Base Score 4.9 (Confidentiality impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).
CVE-2018-2647
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
Server: Replication). Supported versions that are affected are 5.6.38 and prior
and 5.7.20 and prior. Easily exploitable vulnerability allows high privileged
attacker with network access via multiple protocols to compromise MySQL Server.
Successful attacks of this vulnerability can result in unauthorized ability to
cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as
well as unauthorized update, insert or delete access to some of MySQL Server
accessible data. CVSS 3.0 Base Score 5.5 (Integrity and Availability impacts).
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).
CVE-2018-2665
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
Server: Optimizer). Supported versions that are affected are 5.5.58 and prior,
5.6.38 and prior and 5.7.20 and prior. Easily exploitable vulnerability allows
low privileged attacker with network access via multiple protocols to compromise
MySQL Server. Successful attacks of this vulnerability can result in
unauthorized ability to cause a hang or frequently repeatable crash (complete
DOS) of MySQL Server. CVSS 3.0 Base Score 6.5 (Availability impacts). CVSS
Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
CVE-2018-2668
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
Server: Optimizer). Supported versions that are affected are 5.5.58 and prior,
5.6.38 and prior and 5.7.20 and prior. Easily exploitable vulnerability allows
low privileged attacker with network access via multiple protocols to compromise
MySQL Server. Successful attacks of this vulnerability can result in
unauthorized ability to cause a hang or frequently repeatable crash (complete
DOS) of MySQL Server. CVSS 3.0 Base Score 6.5 (Availability impacts). CVSS
Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
CVE-2018-2696
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
Server : Security : Privileges). Supported versions that are affected are 5.6.38
and prior and 5.7.20 and prior. Easily exploitable vulnerability allows
unauthenticated attacker with network access via multiple protocols to
compromise MySQL Server. Successful attacks of this vulnerability can result in
unauthorized ability to cause a hang or frequently repeatable crash (complete
DOS) of MySQL Server. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS
Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
CVE-2018-2703
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
Server : Security : Privileges). Supported versions that are affected are 5.6.38
and prior and 5.7.20 and prior. Easily exploitable vulnerability allows low
privileged attacker with network access via multiple protocols to compromise
MySQL Server. Successful attacks of this vulnerability can result in
unauthorized ability to cause a hang or frequently repeatable crash (complete
DOS) of MySQL Server. CVSS 3.0 Base Score 6.5 (Availability impacts). CVSS
Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

解決策: 

Update packages.

追加情報: 

N/A

ダウンロード: 

SRPMS
  1. rh-mysql56-mysql-5.6.39-1.AXS4.1.src.rpm
    MD5: 8336781f999d4a3882d5247cea2e8462
    SHA-256: 16a4f239f750810c7d187728a4b6776c7a5851bb7d08bf5c1f8080051ff53348
    Size: 29.09 MB

Asianux Server 4 for x86_64
  1. rh-mysql56-mysql-5.6.39-1.AXS4.1.x86_64.rpm
    MD5: 1ffc9d7d294346558a08f2c69c2470d9
    SHA-256: a837261fa54b16c037b8c568ec3bd39815a413147b3d172fc30ead88535d649e
    Size: 7.46 MB
  2. rh-mysql56-mysql-bench-5.6.39-1.AXS4.1.x86_64.rpm
    MD5: 8945220c710a05bc8fb279844c12a9c6
    SHA-256: 9066fe2538853b6e722bd2f8dc6983206a1f98b7945b1a036a0b30cc2695bf3e
    Size: 442.41 kB
  3. rh-mysql56-mysql-common-5.6.39-1.AXS4.1.x86_64.rpm
    MD5: bb4daef92ce3e417bafffbf8902e0533
    SHA-256: 54af43817053db7dcc85f5ea72744721316a8c686eef27f4333e19b3ab5edffb
    Size: 87.97 kB
  4. rh-mysql56-mysql-config-5.6.39-1.AXS4.1.x86_64.rpm
    MD5: 3bf2f75e03469ac0417a10455da5a133
    SHA-256: 94721b4ce5f8cdf0156a28848ad066cdcacd6a50588cf24d9f5b85373c02da36
    Size: 59.99 kB
  5. rh-mysql56-mysql-devel-5.6.39-1.AXS4.1.x86_64.rpm
    MD5: 8487555902117d1d4b9c81bb97bfaea2
    SHA-256: 7e42df81fbb6f84dc2526f15f5e23e831c02d34f22d2ee34958e3c61ee14068c
    Size: 219.21 kB
  6. rh-mysql56-mysql-errmsg-5.6.39-1.AXS4.1.x86_64.rpm
    MD5: 7791bd0baf970120e2ca427bc09a2054
    SHA-256: f132cc7529371e0b554e6c6d28849cab1bb401eb944c46a3e4e44c9b4d693a69
    Size: 309.52 kB
  7. rh-mysql56-mysql-server-5.6.39-1.AXS4.1.x86_64.rpm
    MD5: 08fee776152bcffb16253607c2d0a723
    SHA-256: d9a05c03fad288dc69057b811a1041792522372510bd0ca229ef1e23132f883a
    Size: 12.06 MB
  8. rh-mysql56-mysql-test-5.6.39-1.AXS4.1.x86_64.rpm
    MD5: 22602be8a558631515f6b35b79761434
    SHA-256: 80a4f74380c76561e361f2feafa8fa2f15ce6a9a69a86c2170b53a86e4d53d46
    Size: 10.51 MB