[GLSA-201908-24] MariaDB, MySQL: Multiple vulnerabilities

Severity Normal
Affected Packages 4
Unaffected Packages 4
CVEs 30

Multiple vulnerabilities have been found in MariaDB and MySQL, the worst of which could result in privilege escalation.

Background
MariaDB is an enhanced, drop-in replacement for MySQL. MySQL is a
popular multi-threaded, multi-user SQL server. MySQL is a popular
multi-threaded, multi-user SQL server

Description
Multiple vulnerabilities have been discovered in MariaDB and MySQL.
Please review the CVE identifiers referenced below for details.

Impact
Please review the referenced CVE identifiers for details.

Workaround
There is no known workaround at this time.

Resolution
All MariaDB 10.1.x users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=dev-db/mariadb-10.1.38-r1"

All MariaDB 10.2.x users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=dev-db/mariadb-10.2.22"

All MySQL 5.6.x users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=dev-db/mysql-5.6.42"

All MySQL 5.7.x users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=dev-db/mysql-5.7.24"

ID
GLSA-201908-24
Severity
normal
URL
https://security.gentoo.org/glsa/201908-24
Published
2019-08-18T00:00:00
(5 years ago)
Modified
2019-08-18T00:00:00
(5 years ago)
Rights
Gentoo Foundation, Inc.
Other Advisories
Source # ID Name URL
CVE CVE-2018-2755 CVE-2018-2755 https://nvd.nist.gov/vuln/detail/CVE-2018-2755
CVE CVE-2018-2759 CVE-2018-2759 https://nvd.nist.gov/vuln/detail/CVE-2018-2759
CVE CVE-2018-2761 CVE-2018-2761 https://nvd.nist.gov/vuln/detail/CVE-2018-2761
CVE CVE-2018-2766 CVE-2018-2766 https://nvd.nist.gov/vuln/detail/CVE-2018-2766
CVE CVE-2018-2771 CVE-2018-2771 https://nvd.nist.gov/vuln/detail/CVE-2018-2771
CVE CVE-2018-2777 CVE-2018-2777 https://nvd.nist.gov/vuln/detail/CVE-2018-2777
CVE CVE-2018-2781 CVE-2018-2781 https://nvd.nist.gov/vuln/detail/CVE-2018-2781
CVE CVE-2018-2782 CVE-2018-2782 https://nvd.nist.gov/vuln/detail/CVE-2018-2782
CVE CVE-2018-2784 CVE-2018-2784 https://nvd.nist.gov/vuln/detail/CVE-2018-2784
CVE CVE-2018-2786 CVE-2018-2786 https://nvd.nist.gov/vuln/detail/CVE-2018-2786
CVE CVE-2018-2787 CVE-2018-2787 https://nvd.nist.gov/vuln/detail/CVE-2018-2787
CVE CVE-2018-2810 CVE-2018-2810 https://nvd.nist.gov/vuln/detail/CVE-2018-2810
CVE CVE-2018-2813 CVE-2018-2813 https://nvd.nist.gov/vuln/detail/CVE-2018-2813
CVE CVE-2018-2817 CVE-2018-2817 https://nvd.nist.gov/vuln/detail/CVE-2018-2817
CVE CVE-2018-2819 CVE-2018-2819 https://nvd.nist.gov/vuln/detail/CVE-2018-2819
CVE CVE-2018-3143 CVE-2018-3143 https://nvd.nist.gov/vuln/detail/CVE-2018-3143
CVE CVE-2018-3156 CVE-2018-3156 https://nvd.nist.gov/vuln/detail/CVE-2018-3156
CVE CVE-2018-3162 CVE-2018-3162 https://nvd.nist.gov/vuln/detail/CVE-2018-3162
CVE CVE-2018-3173 CVE-2018-3173 https://nvd.nist.gov/vuln/detail/CVE-2018-3173
CVE CVE-2018-3174 CVE-2018-3174 https://nvd.nist.gov/vuln/detail/CVE-2018-3174
CVE CVE-2018-3185 CVE-2018-3185 https://nvd.nist.gov/vuln/detail/CVE-2018-3185
CVE CVE-2018-3200 CVE-2018-3200 https://nvd.nist.gov/vuln/detail/CVE-2018-3200
CVE CVE-2018-3251 CVE-2018-3251 https://nvd.nist.gov/vuln/detail/CVE-2018-3251
CVE CVE-2018-3252 CVE-2018-3252 https://nvd.nist.gov/vuln/detail/CVE-2018-3252
CVE CVE-2018-3277 CVE-2018-3277 https://nvd.nist.gov/vuln/detail/CVE-2018-3277
CVE CVE-2018-3282 CVE-2018-3282 https://nvd.nist.gov/vuln/detail/CVE-2018-3282
CVE CVE-2018-3284 CVE-2018-3284 https://nvd.nist.gov/vuln/detail/CVE-2018-3284
CVE CVE-2019-2510 CVE-2019-2510 https://nvd.nist.gov/vuln/detail/CVE-2019-2510
CVE CVE-2019-2529 CVE-2019-2529 https://nvd.nist.gov/vuln/detail/CVE-2019-2529
CVE CVE-2019-2537 CVE-2019-2537 https://nvd.nist.gov/vuln/detail/CVE-2019-2537
Bugzilla 661500 Bugzilla #661500 https://bugs.gentoo.org/show_bug.cgi?id=661500
Bugzilla 670388 Bugzilla #670388 https://bugs.gentoo.org/show_bug.cgi?id=670388
Bugzilla 679024 Bugzilla #679024 https://bugs.gentoo.org/show_bug.cgi?id=679024
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:ebuild/dev-db/mysql?distro=gentoo dev-db mysql < 5.6.42 gentoo
Affected pkg:ebuild/dev-db/mysql?distro=gentoo dev-db mysql < 5.7.24 gentoo
Unaffected pkg:ebuild/dev-db/mysql?distro=gentoo dev-db mysql >= 5.6.42 gentoo
Unaffected pkg:ebuild/dev-db/mysql?distro=gentoo dev-db mysql >= 5.7.24 gentoo
Affected pkg:ebuild/dev-db/mariadb?distro=gentoo dev-db mariadb < 10.1.38-r1 gentoo
Affected pkg:ebuild/dev-db/mariadb?distro=gentoo dev-db mariadb < 10.2.22 gentoo
Unaffected pkg:ebuild/dev-db/mariadb?distro=gentoo dev-db mariadb >= 10.1.38-r1 gentoo
Unaffected pkg:ebuild/dev-db/mariadb?distro=gentoo dev-db mariadb >= 10.2.22 gentoo
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...