[RHSA-2015:1665] mariadb security update

Severity Moderate
Affected Packages 36
CVEs 17

MariaDB is a multi-user, multi-threaded SQL database server that is binary
compatible with MySQL.

It was found that the MySQL client library permitted but did not require a
client to use SSL/TLS when establishing a secure connection to a MySQL
server using the "--ssl" option. A man-in-the-middle attacker could use
this flaw to strip the SSL/TLS protection from a connection between a
client and a server. (CVE-2015-3152)

This update fixes several vulnerabilities in the MariaDB database server.
Information about these flaws can be found on the Oracle Critical Patch
Update Advisory page, listed in the References section. (CVE-2015-0501,
CVE-2015-2568, CVE-2015-0499, CVE-2015-2571, CVE-2015-0433, CVE-2015-0441,
CVE-2015-0505, CVE-2015-2573, CVE-2015-2582, CVE-2015-2620, CVE-2015-2643,
CVE-2015-2648, CVE-2015-4737, CVE-2015-4752, CVE-2015-4757)

These updated packages upgrade MariaDB to version 5.5.44. Refer to the
MariaDB Release Notes listed in the References section for a complete list
of changes.

All MariaDB users should upgrade to these updated packages, which correct
these issues. After installing this update, the MariaDB server daemon
(mysqld) will be restarted automatically.

Package Affected Version
pkg:rpm/redhat/mariadb?arch=x86_64&distro=redhat-7.1 < 5.5.44-1.el7_1
pkg:rpm/redhat/mariadb?arch=s390x&distro=redhat-7.1 < 5.5.44-1.el7_1
pkg:rpm/redhat/mariadb?arch=ppc64&distro=redhat-7.1 < 5.5.44-1.el7_1
pkg:rpm/redhat/mariadb-test?arch=x86_64&distro=redhat-7.1 < 5.5.44-1.el7_1
pkg:rpm/redhat/mariadb-test?arch=s390x&distro=redhat-7.1 < 5.5.44-1.el7_1
pkg:rpm/redhat/mariadb-test?arch=ppc64&distro=redhat-7.1 < 5.5.44-1.el7_1
pkg:rpm/redhat/mariadb-server?arch=x86_64&distro=redhat-7.1 < 5.5.44-1.el7_1
pkg:rpm/redhat/mariadb-server?arch=s390x&distro=redhat-7.1 < 5.5.44-1.el7_1
pkg:rpm/redhat/mariadb-server?arch=ppc64&distro=redhat-7.1 < 5.5.44-1.el7_1
pkg:rpm/redhat/mariadb-libs?arch=x86_64&distro=redhat-7.1 < 5.5.44-1.el7_1
pkg:rpm/redhat/mariadb-libs?arch=s390x&distro=redhat-7.1 < 5.5.44-1.el7_1
pkg:rpm/redhat/mariadb-libs?arch=s390&distro=redhat-7.1 < 5.5.44-1.el7_1
pkg:rpm/redhat/mariadb-libs?arch=ppc64&distro=redhat-7.1 < 5.5.44-1.el7_1
pkg:rpm/redhat/mariadb-libs?arch=ppc&distro=redhat-7.1 < 5.5.44-1.el7_1
pkg:rpm/redhat/mariadb-libs?arch=i686&distro=redhat-7.1 < 5.5.44-1.el7_1
pkg:rpm/redhat/mariadb-embedded?arch=x86_64&distro=redhat-7.1 < 5.5.44-1.el7_1
pkg:rpm/redhat/mariadb-embedded?arch=s390x&distro=redhat-7.1 < 5.5.44-1.el7_1
pkg:rpm/redhat/mariadb-embedded?arch=s390&distro=redhat-7.1 < 5.5.44-1.el7_1
pkg:rpm/redhat/mariadb-embedded?arch=ppc64&distro=redhat-7.1 < 5.5.44-1.el7_1
pkg:rpm/redhat/mariadb-embedded?arch=ppc&distro=redhat-7.1 < 5.5.44-1.el7_1
pkg:rpm/redhat/mariadb-embedded?arch=i686&distro=redhat-7.1 < 5.5.44-1.el7_1
pkg:rpm/redhat/mariadb-embedded-devel?arch=x86_64&distro=redhat-7.1 < 5.5.44-1.el7_1
pkg:rpm/redhat/mariadb-embedded-devel?arch=s390x&distro=redhat-7.1 < 5.5.44-1.el7_1
pkg:rpm/redhat/mariadb-embedded-devel?arch=s390&distro=redhat-7.1 < 5.5.44-1.el7_1
pkg:rpm/redhat/mariadb-embedded-devel?arch=ppc64&distro=redhat-7.1 < 5.5.44-1.el7_1
pkg:rpm/redhat/mariadb-embedded-devel?arch=ppc&distro=redhat-7.1 < 5.5.44-1.el7_1
pkg:rpm/redhat/mariadb-embedded-devel?arch=i686&distro=redhat-7.1 < 5.5.44-1.el7_1
pkg:rpm/redhat/mariadb-devel?arch=x86_64&distro=redhat-7.1 < 5.5.44-1.el7_1
pkg:rpm/redhat/mariadb-devel?arch=s390x&distro=redhat-7.1 < 5.5.44-1.el7_1
pkg:rpm/redhat/mariadb-devel?arch=s390&distro=redhat-7.1 < 5.5.44-1.el7_1
pkg:rpm/redhat/mariadb-devel?arch=ppc64&distro=redhat-7.1 < 5.5.44-1.el7_1
pkg:rpm/redhat/mariadb-devel?arch=ppc&distro=redhat-7.1 < 5.5.44-1.el7_1
pkg:rpm/redhat/mariadb-devel?arch=i686&distro=redhat-7.1 < 5.5.44-1.el7_1
pkg:rpm/redhat/mariadb-bench?arch=x86_64&distro=redhat-7.1 < 5.5.44-1.el7_1
pkg:rpm/redhat/mariadb-bench?arch=s390x&distro=redhat-7.1 < 5.5.44-1.el7_1
pkg:rpm/redhat/mariadb-bench?arch=ppc64&distro=redhat-7.1 < 5.5.44-1.el7_1
Source # ID Name URL
Bugzilla 1212758 https://bugzilla.redhat.com/1212758
Bugzilla 1212763 https://bugzilla.redhat.com/1212763
Bugzilla 1212768 https://bugzilla.redhat.com/1212768
Bugzilla 1212772 https://bugzilla.redhat.com/1212772
Bugzilla 1212776 https://bugzilla.redhat.com/1212776
Bugzilla 1212777 https://bugzilla.redhat.com/1212777
Bugzilla 1212780 https://bugzilla.redhat.com/1212780
Bugzilla 1212783 https://bugzilla.redhat.com/1212783
Bugzilla 1217506 https://bugzilla.redhat.com/1217506
Bugzilla 1244768 https://bugzilla.redhat.com/1244768
Bugzilla 1244771 https://bugzilla.redhat.com/1244771
Bugzilla 1244774 https://bugzilla.redhat.com/1244774
Bugzilla 1244775 https://bugzilla.redhat.com/1244775
Bugzilla 1244778 https://bugzilla.redhat.com/1244778
Bugzilla 1244779 https://bugzilla.redhat.com/1244779
Bugzilla 1244781 https://bugzilla.redhat.com/1244781
Bugzilla 1274779 https://bugzilla.redhat.com/1274779
RHSA RHSA-2015:1665 https://access.redhat.com/errata/RHSA-2015:1665
CVE CVE-2015-0433 https://access.redhat.com/security/cve/CVE-2015-0433
CVE CVE-2015-0441 https://access.redhat.com/security/cve/CVE-2015-0441
CVE CVE-2015-0499 https://access.redhat.com/security/cve/CVE-2015-0499
CVE CVE-2015-0501 https://access.redhat.com/security/cve/CVE-2015-0501
CVE CVE-2015-0505 https://access.redhat.com/security/cve/CVE-2015-0505
CVE CVE-2015-2568 https://access.redhat.com/security/cve/CVE-2015-2568
CVE CVE-2015-2571 https://access.redhat.com/security/cve/CVE-2015-2571
CVE CVE-2015-2573 https://access.redhat.com/security/cve/CVE-2015-2573
CVE CVE-2015-2582 https://access.redhat.com/security/cve/CVE-2015-2582
CVE CVE-2015-2620 https://access.redhat.com/security/cve/CVE-2015-2620
CVE CVE-2015-2643 https://access.redhat.com/security/cve/CVE-2015-2643
CVE CVE-2015-2648 https://access.redhat.com/security/cve/CVE-2015-2648
CVE CVE-2015-3152 https://access.redhat.com/security/cve/CVE-2015-3152
CVE CVE-2015-4737 https://access.redhat.com/security/cve/CVE-2015-4737
CVE CVE-2015-4752 https://access.redhat.com/security/cve/CVE-2015-4752
CVE CVE-2015-4757 https://access.redhat.com/security/cve/CVE-2015-4757
CVE CVE-2015-4864 https://access.redhat.com/security/cve/CVE-2015-4864
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/redhat/mariadb?arch=x86_64&distro=redhat-7.1 redhat mariadb < 5.5.44-1.el7_1 redhat-7.1 x86_64
Affected pkg:rpm/redhat/mariadb?arch=s390x&distro=redhat-7.1 redhat mariadb < 5.5.44-1.el7_1 redhat-7.1 s390x
Affected pkg:rpm/redhat/mariadb?arch=ppc64&distro=redhat-7.1 redhat mariadb < 5.5.44-1.el7_1 redhat-7.1 ppc64
Affected pkg:rpm/redhat/mariadb-test?arch=x86_64&distro=redhat-7.1 redhat mariadb-test < 5.5.44-1.el7_1 redhat-7.1 x86_64
Affected pkg:rpm/redhat/mariadb-test?arch=s390x&distro=redhat-7.1 redhat mariadb-test < 5.5.44-1.el7_1 redhat-7.1 s390x
Affected pkg:rpm/redhat/mariadb-test?arch=ppc64&distro=redhat-7.1 redhat mariadb-test < 5.5.44-1.el7_1 redhat-7.1 ppc64
Affected pkg:rpm/redhat/mariadb-server?arch=x86_64&distro=redhat-7.1 redhat mariadb-server < 5.5.44-1.el7_1 redhat-7.1 x86_64
Affected pkg:rpm/redhat/mariadb-server?arch=s390x&distro=redhat-7.1 redhat mariadb-server < 5.5.44-1.el7_1 redhat-7.1 s390x
Affected pkg:rpm/redhat/mariadb-server?arch=ppc64&distro=redhat-7.1 redhat mariadb-server < 5.5.44-1.el7_1 redhat-7.1 ppc64
Affected pkg:rpm/redhat/mariadb-libs?arch=x86_64&distro=redhat-7.1 redhat mariadb-libs < 5.5.44-1.el7_1 redhat-7.1 x86_64
Affected pkg:rpm/redhat/mariadb-libs?arch=s390x&distro=redhat-7.1 redhat mariadb-libs < 5.5.44-1.el7_1 redhat-7.1 s390x
Affected pkg:rpm/redhat/mariadb-libs?arch=s390&distro=redhat-7.1 redhat mariadb-libs < 5.5.44-1.el7_1 redhat-7.1 s390
Affected pkg:rpm/redhat/mariadb-libs?arch=ppc64&distro=redhat-7.1 redhat mariadb-libs < 5.5.44-1.el7_1 redhat-7.1 ppc64
Affected pkg:rpm/redhat/mariadb-libs?arch=ppc&distro=redhat-7.1 redhat mariadb-libs < 5.5.44-1.el7_1 redhat-7.1 ppc
Affected pkg:rpm/redhat/mariadb-libs?arch=i686&distro=redhat-7.1 redhat mariadb-libs < 5.5.44-1.el7_1 redhat-7.1 i686
Affected pkg:rpm/redhat/mariadb-embedded?arch=x86_64&distro=redhat-7.1 redhat mariadb-embedded < 5.5.44-1.el7_1 redhat-7.1 x86_64
Affected pkg:rpm/redhat/mariadb-embedded?arch=s390x&distro=redhat-7.1 redhat mariadb-embedded < 5.5.44-1.el7_1 redhat-7.1 s390x
Affected pkg:rpm/redhat/mariadb-embedded?arch=s390&distro=redhat-7.1 redhat mariadb-embedded < 5.5.44-1.el7_1 redhat-7.1 s390
Affected pkg:rpm/redhat/mariadb-embedded?arch=ppc64&distro=redhat-7.1 redhat mariadb-embedded < 5.5.44-1.el7_1 redhat-7.1 ppc64
Affected pkg:rpm/redhat/mariadb-embedded?arch=ppc&distro=redhat-7.1 redhat mariadb-embedded < 5.5.44-1.el7_1 redhat-7.1 ppc
Affected pkg:rpm/redhat/mariadb-embedded?arch=i686&distro=redhat-7.1 redhat mariadb-embedded < 5.5.44-1.el7_1 redhat-7.1 i686
Affected pkg:rpm/redhat/mariadb-embedded-devel?arch=x86_64&distro=redhat-7.1 redhat mariadb-embedded-devel < 5.5.44-1.el7_1 redhat-7.1 x86_64
Affected pkg:rpm/redhat/mariadb-embedded-devel?arch=s390x&distro=redhat-7.1 redhat mariadb-embedded-devel < 5.5.44-1.el7_1 redhat-7.1 s390x
Affected pkg:rpm/redhat/mariadb-embedded-devel?arch=s390&distro=redhat-7.1 redhat mariadb-embedded-devel < 5.5.44-1.el7_1 redhat-7.1 s390
Affected pkg:rpm/redhat/mariadb-embedded-devel?arch=ppc64&distro=redhat-7.1 redhat mariadb-embedded-devel < 5.5.44-1.el7_1 redhat-7.1 ppc64
Affected pkg:rpm/redhat/mariadb-embedded-devel?arch=ppc&distro=redhat-7.1 redhat mariadb-embedded-devel < 5.5.44-1.el7_1 redhat-7.1 ppc
Affected pkg:rpm/redhat/mariadb-embedded-devel?arch=i686&distro=redhat-7.1 redhat mariadb-embedded-devel < 5.5.44-1.el7_1 redhat-7.1 i686
Affected pkg:rpm/redhat/mariadb-devel?arch=x86_64&distro=redhat-7.1 redhat mariadb-devel < 5.5.44-1.el7_1 redhat-7.1 x86_64
Affected pkg:rpm/redhat/mariadb-devel?arch=s390x&distro=redhat-7.1 redhat mariadb-devel < 5.5.44-1.el7_1 redhat-7.1 s390x
Affected pkg:rpm/redhat/mariadb-devel?arch=s390&distro=redhat-7.1 redhat mariadb-devel < 5.5.44-1.el7_1 redhat-7.1 s390
Affected pkg:rpm/redhat/mariadb-devel?arch=ppc64&distro=redhat-7.1 redhat mariadb-devel < 5.5.44-1.el7_1 redhat-7.1 ppc64
Affected pkg:rpm/redhat/mariadb-devel?arch=ppc&distro=redhat-7.1 redhat mariadb-devel < 5.5.44-1.el7_1 redhat-7.1 ppc
Affected pkg:rpm/redhat/mariadb-devel?arch=i686&distro=redhat-7.1 redhat mariadb-devel < 5.5.44-1.el7_1 redhat-7.1 i686
Affected pkg:rpm/redhat/mariadb-bench?arch=x86_64&distro=redhat-7.1 redhat mariadb-bench < 5.5.44-1.el7_1 redhat-7.1 x86_64
Affected pkg:rpm/redhat/mariadb-bench?arch=s390x&distro=redhat-7.1 redhat mariadb-bench < 5.5.44-1.el7_1 redhat-7.1 s390x
Affected pkg:rpm/redhat/mariadb-bench?arch=ppc64&distro=redhat-7.1 redhat mariadb-bench < 5.5.44-1.el7_1 redhat-7.1 ppc64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...