rh-mysql56-mysql-5.6.39-1.el7.1

エラータID: AXSA:2018-2639:01

リリース日: 
2018/03/29 Thursday - 14:19
題名: 
rh-mysql56-mysql-5.6.39-1.el7.1
影響のあるチャネル: 
Asianux Server 7 for x86_64
Severity: 
Moderate
Description: 

MySQL is a multi-user, multi-threaded SQL database server. It consists of the
MySQL server daemon, mysqld, and many client programs.

The following packages have been upgraded to a later upstream version:
rh-mysql56-mysql (5.6.39). (BZ#1533831)

Security Fix(es):

* mysql: sha256_password authentication DoS via long password (CVE-2018-2696)

* mysql: Server : Partition unspecified vulnerability (CPU Jan 2018)
(CVE-2018-2562)

* mysql: Server: GIS unspecified vulnerability (CPU Jan 2018) (CVE-2018-2573)

* mysql: Stored Procedure unspecified vulnerability (CPU Jan 2018)
(CVE-2018-2583)

* mysql: Server: Performance Schema unspecified vulnerability (CPU Jan 2018)
(CVE-2018-2590)

* mysql: Server : Partition unspecified vulnerability (CPU Jan 2018)
(CVE-2018-2591)

* mysql: InnoDB unspecified vulnerability (CPU Jan 2018) (CVE-2018-2612)

* mysql: Server: DDL unspecified vulnerability (CPU Jan 2018) (CVE-2018-2622)

* mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2018)
(CVE-2018-2640)

* mysql: Server: Performance Schema unspecified vulnerability (CPU Jan 2018)
(CVE-2018-2645)

* mysql: Server: Replication unspecified vulnerability (CPU Jan 2018)
(CVE-2018-2647)

* mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2018)
(CVE-2018-2665)

* mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2018)
(CVE-2018-2668)

* mysql: sha256_password authentication DoS via hash with large rounds value
(CVE-2018-2703)

For more details about the security issue(s), including the impact, a CVSS
score, and other related information, refer to the CVE page(s) listed in the
References section.

CVE-2018-2562
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
Server : Partition). Supported versions that are affected are 5.5.58 and prior,
5.6.38 and prior and 5.7.19 and prior. Easily exploitable vulnerability allows
low privileged attacker with network access via multiple protocols to compromise
MySQL Server. Successful attacks of this vulnerability can result in
unauthorized ability to cause a hang or frequently repeatable crash (complete
DOS) of MySQL Server as well as unauthorized update, insert or delete access to
some of MySQL Server accessible data. CVSS 3.0 Base Score 7.1 (Integrity and
Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H).
CVE-2018-2573
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
Server: GIS). Supported versions that are affected are 5.6.38 and prior and
5.7.20 and prior. Easily exploitable vulnerability allows low privileged
attacker with network access via multiple protocols to compromise MySQL Server.
Successful attacks of this vulnerability can result in unauthorized ability to
cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS
3.0 Base Score 6.5 (Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
CVE-2018-2583
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
Stored Procedure). Supported versions that are affected are 5.6.38 and prior and
5.7.20 and prior. Easily exploitable vulnerability allows high privileged
attacker with network access via multiple protocols to compromise MySQL Server.
While the vulnerability is in MySQL Server, attacks may significantly impact
additional products. Successful attacks of this vulnerability can result in
unauthorized ability to cause a hang or frequently repeatable crash (complete
DOS) of MySQL Server. CVSS 3.0 Base Score 6.8 (Availability impacts). CVSS
Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H).
CVE-2018-2590
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
Server: Performance Schema). Supported versions that are affected are 5.6.38 and
prior and 5.7.20 and prior. Easily exploitable vulnerability allows high
privileged attacker with network access via multiple protocols to compromise
MySQL Server. Successful attacks of this vulnerability can result in
unauthorized ability to cause a hang or frequently repeatable crash (complete
DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS
Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2018-2591
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
Server : Partition). Supported versions that are affected are 5.6.38 and prior
and 5.7.19 and prior. Easily exploitable vulnerability allows high privileged
attacker with network access via multiple protocols to compromise MySQL Server.
Successful attacks of this vulnerability can result in unauthorized ability to
cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS
3.0 Base Score 4.9 (Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2018-2612
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
InnoDB). Supported versions that are affected are 5.6.38 and prior and 5.7.20
and prior. Easily exploitable vulnerability allows high privileged attacker with
network access via multiple protocols to compromise MySQL Server. Successful
attacks of this vulnerability can result in unauthorized creation, deletion or
modification access to critical data or all MySQL Server accessible data and
unauthorized ability to cause a hang or frequently repeatable crash (complete
DOS) of MySQL Server. CVSS 3.0 Base Score 6.5 (Integrity and Availability
impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H).
CVE-2018-2622
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
Server: DDL). Supported versions that are affected are 5.5.58 and prior, 5.6.38
and prior and 5.7.20 and prior. Easily exploitable vulnerability allows low
privileged attacker with network access via multiple protocols to compromise
MySQL Server. Successful attacks of this vulnerability can result in
unauthorized ability to cause a hang or frequently repeatable crash (complete
DOS) of MySQL Server. CVSS 3.0 Base Score 6.5 (Availability impacts). CVSS
Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
CVE-2018-2640
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
Server: Optimizer). Supported versions that are affected are 5.5.58 and prior,
5.6.38 and prior and 5.7.20 and prior. Easily exploitable vulnerability allows
low privileged attacker with network access via multiple protocols to compromise
MySQL Server. Successful attacks of this vulnerability can result in
unauthorized ability to cause a hang or frequently repeatable crash (complete
DOS) of MySQL Server. CVSS 3.0 Base Score 6.5 (Availability impacts). CVSS
Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
CVE-2018-2645
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
Server: Performance Schema). Supported versions that are affected are 5.6.38 and
prior and 5.7.20 and prior. Easily exploitable vulnerability allows high
privileged attacker with network access via multiple protocols to compromise
MySQL Server. Successful attacks of this vulnerability can result in
unauthorized access to critical data or complete access to all MySQL Server
accessible data. CVSS 3.0 Base Score 4.9 (Confidentiality impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).
CVE-2018-2647
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
Server: Replication). Supported versions that are affected are 5.6.38 and prior
and 5.7.20 and prior. Easily exploitable vulnerability allows high privileged
attacker with network access via multiple protocols to compromise MySQL Server.
Successful attacks of this vulnerability can result in unauthorized ability to
cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as
well as unauthorized update, insert or delete access to some of MySQL Server
accessible data. CVSS 3.0 Base Score 5.5 (Integrity and Availability impacts).
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).
CVE-2018-2665
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
Server: Optimizer). Supported versions that are affected are 5.5.58 and prior,
5.6.38 and prior and 5.7.20 and prior. Easily exploitable vulnerability allows
low privileged attacker with network access via multiple protocols to compromise
MySQL Server. Successful attacks of this vulnerability can result in
unauthorized ability to cause a hang or frequently repeatable crash (complete
DOS) of MySQL Server. CVSS 3.0 Base Score 6.5 (Availability impacts). CVSS
Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
CVE-2018-2668
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
Server: Optimizer). Supported versions that are affected are 5.5.58 and prior,
5.6.38 and prior and 5.7.20 and prior. Easily exploitable vulnerability allows
low privileged attacker with network access via multiple protocols to compromise
MySQL Server. Successful attacks of this vulnerability can result in
unauthorized ability to cause a hang or frequently repeatable crash (complete
DOS) of MySQL Server. CVSS 3.0 Base Score 6.5 (Availability impacts). CVSS
Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
CVE-2018-2696
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
Server : Security : Privileges). Supported versions that are affected are 5.6.38
and prior and 5.7.20 and prior. Easily exploitable vulnerability allows
unauthenticated attacker with network access via multiple protocols to
compromise MySQL Server. Successful attacks of this vulnerability can result in
unauthorized ability to cause a hang or frequently repeatable crash (complete
DOS) of MySQL Server. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS
Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
CVE-2018-2703
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
Server : Security : Privileges). Supported versions that are affected are 5.6.38
and prior and 5.7.20 and prior. Easily exploitable vulnerability allows low
privileged attacker with network access via multiple protocols to compromise
MySQL Server. Successful attacks of this vulnerability can result in
unauthorized ability to cause a hang or frequently repeatable crash (complete
DOS) of MySQL Server. CVSS 3.0 Base Score 6.5 (Availability impacts). CVSS
Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

解決策: 

Update packages.

追加情報: 

N/A

ダウンロード: 

SRPMS
  1. rh-mysql56-mysql-5.6.39-1.el7.1.src.rpm
    MD5: 046fe0256e5795ca206423ccb5b9d461
    SHA-256: e6a6c8378e0b43e761eaea675e5c1e0721f191ab836aabba08e10c50ad572f67
    Size: 29.09 MB

Asianux Server 7 for x86_64
  1. rh-mysql56-mysql-5.6.39-1.el7.1.x86_64.rpm
    MD5: 094d9e7b46fb6a768e9b474cf7c8d35e
    SHA-256: 259ca006375b646d8741b4908fd84f1eb5cdf097ef21550e1321ccb9fc7fab48
    Size: 6.59 MB
  2. rh-mysql56-mysql-bench-5.6.39-1.el7.1.x86_64.rpm
    MD5: 6266537bafd357e316f9a858a2caa9ed
    SHA-256: d2b7c8767692ef815afbbfa9e0057a7d544aa7052d3343b38ac99f026038fa48
    Size: 432.81 kB
  3. rh-mysql56-mysql-common-5.6.39-1.el7.1.x86_64.rpm
    MD5: c40ab29a4fe4ea9704e3d4cce4f3dd90
    SHA-256: 2325a4a180c0778edec2bea3b76e09dbf206bd42df272714aeb711df52f43038
    Size: 88.49 kB
  4. rh-mysql56-mysql-config-5.6.39-1.el7.1.x86_64.rpm
    MD5: 50e74da625f9e72ddabe166486296c27
    SHA-256: 885c641443467d89798f14ba3c11b662a254fd9f03a3b231ccf444123e3ade7d
    Size: 60.29 kB
  5. rh-mysql56-mysql-devel-5.6.39-1.el7.1.x86_64.rpm
    MD5: 492551aa6629562d114a38337da4f9c2
    SHA-256: efaa59a57770f0eb91416e4815de7960d97bfb0da3f6555c2c071fb70ed3bc7a
    Size: 219.71 kB
  6. rh-mysql56-mysql-errmsg-5.6.39-1.el7.1.x86_64.rpm
    MD5: 043242fca4b333a07f41a13445ad4d56
    SHA-256: 4366f92a5081fb3c0e790ba4cfc020fee1703ec5e72da3fa44644f46a7036e1b
    Size: 259.71 kB
  7. rh-mysql56-mysql-server-5.6.39-1.el7.1.x86_64.rpm
    MD5: 3178934b1139ee841b06b2b7d43459a4
    SHA-256: 2a3d9f7b31de3b3228575baf8a17929f1b9fc2fc1c35f80d9e0080d2287034e3
    Size: 11.02 MB
  8. rh-mysql56-mysql-test-5.6.39-1.el7.1.x86_64.rpm
    MD5: 584b99ead473d844dfc5859ced22ed4a
    SHA-256: c27614f2c44928403d42c4976836f382bf39352b475ea85ac6f56c1c817baed2
    Size: 9.55 MB