SUSE-SU-2019:2461-1: moderate: Security update for mariadb

sle-security-updates at lists.suse.com sle-security-updates at lists.suse.com
Wed Sep 25 13:11:21 MDT 2019


   SUSE Security Update: Security update for mariadb
______________________________________________________________________________

Announcement ID:    SUSE-SU-2019:2461-1
Rating:             moderate
References:         #1127027 #1132826 #1141798 #1142058 #1143215 
                    
Cross-References:   CVE-2019-2614 CVE-2019-2627 CVE-2019-2737
                    CVE-2019-2739 CVE-2019-2740 CVE-2019-2805
                   
Affected Products:
                    SUSE OpenStack Cloud Crowbar 8
                    SUSE OpenStack Cloud 8
                    HPE Helion Openstack 8
______________________________________________________________________________

   An update that fixes 6 vulnerabilities is now available.

Description:

   This update for mariadb fixes the following issues:

   Updated to MariaDB 10.0.40-1.

   Security issues fixed:

   - CVE-2019-2805, CVE-2019-2740, CVE-2019-2739, CVE-2019-2737,
     CVE-2019-2614, CVE-2019-2627. (bsc#1132826) (bsc#1141798).

   Non-security issues fixed:

   - Adjusted mysql-systemd-helper ("shutdown protected MySQL" section) so it
     checks both ping response and the pid in a process list as it can take
     some time till the process is terminated. Otherwise it can lead to
     "found left-over process" situation when regular mariadb is started.
     (bsc#1143215)
   - Fixed IP resolving in mysql_install_db script. (bsc#1142058,
     bsc#1127027, MDEV-18526)


Patch Instructions:

   To install this SUSE Security Update use the SUSE recommended installation methods
   like YaST online_update or "zypper patch".

   Alternatively you can run the command listed for your product:

   - SUSE OpenStack Cloud Crowbar 8:

      zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2019-2461=1

   - SUSE OpenStack Cloud 8:

      zypper in -t patch SUSE-OpenStack-Cloud-8-2019-2461=1

   - HPE Helion Openstack 8:

      zypper in -t patch HPE-Helion-OpenStack-8-2019-2461=1



Package List:

   - SUSE OpenStack Cloud Crowbar 8 (x86_64):

      libmysqlclient18-10.0.40.1-29.32.1
      libmysqlclient18-debuginfo-10.0.40.1-29.32.1

   - SUSE OpenStack Cloud 8 (x86_64):

      libmysqlclient18-10.0.40.1-29.32.1
      libmysqlclient18-debuginfo-10.0.40.1-29.32.1

   - HPE Helion Openstack 8 (x86_64):

      libmysqlclient18-10.0.40.1-29.32.1
      libmysqlclient18-debuginfo-10.0.40.1-29.32.1


References:

   https://www.suse.com/security/cve/CVE-2019-2614.html
   https://www.suse.com/security/cve/CVE-2019-2627.html
   https://www.suse.com/security/cve/CVE-2019-2737.html
   https://www.suse.com/security/cve/CVE-2019-2739.html
   https://www.suse.com/security/cve/CVE-2019-2740.html
   https://www.suse.com/security/cve/CVE-2019-2805.html
   https://bugzilla.suse.com/1127027
   https://bugzilla.suse.com/1132826
   https://bugzilla.suse.com/1141798
   https://bugzilla.suse.com/1142058
   https://bugzilla.suse.com/1143215



More information about the sle-security-updates mailing list