Bugzilla – Full Text Bug Listing |
Summary: | VUL-0: CVE-2017-3313: mariadb,mysql: unspecified vulnerability affecting the MyISAM component (CPU Jan 2017) | ||
---|---|---|---|
Product: | [Novell Products] SUSE Security Incidents | Reporter: | Andreas Stieger <astieger> |
Component: | Incidents | Assignee: | Security Team bot <security-team> |
Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
Severity: | Minor | ||
Priority: | P3 - Medium | CC: | kstreitova, smash_bz |
Version: | unspecified | ||
Target Milestone: | --- | ||
Hardware: | Other | ||
OS: | Other | ||
URL: | https://smash.suse.de/issue/178829/ | ||
Whiteboard: | CVSSv2:SUSE:CVE-2017-3313:3.8:(AV:L/AC:H/Au:S/C:C/I:N/A:N) CVSSv2:NVD:CVE-2017-3313:1.5:(AV:L/AC:M/Au:S/C:P/I:N/A:N) maint:running:63379:important maint:released:oes2015:63391 CVSSv3:NVD:CVE-2017-3313:4.7:(AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N) CVSSv3:RedHat:CVE-2017-3313:4.7:(AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N) CVSSv2:NVD:CVE-2016-5616:4.4:(AV:L/AC:M/Au:N/C:P/I:P/A:P) CVSSv2:NVD:CVE-2016-5617:4.4:(AV:L/AC:M/Au:N/C:P/I:P/A:P) CVSSv2:RedHat:CVE-2016-5616:3.5:(AV:L/AC:H/Au:S/C:P/I:P/A:P) CVSSv2:RedHat:CVE-2016-5617:6.8:(AV:L/AC:L/Au:S/C:C/I:C/A:C) CVSSv2:SUSE:CVE-2016-5616:6.0:(AV:L/AC:H/Au:S/C:C/I:C/A:C) CVSSv3:RedHat:CVE-2016-5483:6.4:(AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H) CVSSv3:RedHat:CVE-2016-5616:7.0:(AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H) CVSSv3:RedHat:CVE-2016-5617:7.8:(AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) CVSSv3:UNK(Oracle):CVE-2016-5616:7.0:(AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H) CVSSv3:UNK(Oracle):CVE-2016-5617:7.0:(AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H) CVSSv3:UNK(Oracle):CVE-2017-3313:4.7:(AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N) CVSSv2:RedHat:CVE-2016-5616:6.0:(AV:L/AC:H/Au:S/C:C/I:C/A:C) | ||
Found By: | Security Response Team | Services Priority: | |
Business Priority: | Blocker: | --- | |
Marketing QA Status: | --- | IT Deployment: | --- |
Bug Depends on: | |||
Bug Blocks: | 1020868 |
Description
Andreas Stieger
2017-01-19 12:35:14 UTC
bugbot adjusting priority SUSE-SU-2017:0408-1: An update that solves 10 vulnerabilities and has two fixes is now available. Category: security (important) Bug References: 1020868,1020873,1020875,1020877,1020882,1020884,1020885,1020890,1020891,1020894,1020896,1022428 CVE References: CVE-2017-3238,CVE-2017-3243,CVE-2017-3244,CVE-2017-3258,CVE-2017-3265,CVE-2017-3291,CVE-2017-3312,CVE-2017-3313,CVE-2017-3317,CVE-2017-3318 Sources used: SUSE OpenStack Cloud 5 (src): mysql-5.5.54-0.35.1 SUSE Manager Proxy 2.1 (src): mysql-5.5.54-0.35.1 SUSE Manager 2.1 (src): mysql-5.5.54-0.35.1 SUSE Linux Enterprise Software Development Kit 11-SP4 (src): mysql-5.5.54-0.35.1 SUSE Linux Enterprise Server 11-SP4 (src): mysql-5.5.54-0.35.1 SUSE Linux Enterprise Server 11-SP3-LTSS (src): mysql-5.5.54-0.35.1 SUSE Linux Enterprise Point of Sale 11-SP3 (src): mysql-5.5.54-0.35.1 SUSE Linux Enterprise Debuginfo 11-SP4 (src): mysql-5.5.54-0.35.1 SUSE Linux Enterprise Debuginfo 11-SP3 (src): mysql-5.5.54-0.35.1 mysql ----- | Codestream | Request | |------------------------|----------| | SUSE:SLE-11-SP3:Update | #127359 | | openSUSE:Leap:42.1 | #455749 | | openSUSE:Leap:42.2 | via 42.1 | | openSUSE:Factory | #455744 | mariadb ------- It's not fixed yet in the MariaDB upstream. I'm reassigning it back to the security-team. Feel free to reassign it back when the mariadb submission is needed. Thanks! This is an autogenerated message for OBS integration: This bug (1020890) was mentioned in https://build.opensuse.org/request/show/455749 42.1 / mysql-community-server openSUSE-SU-2017:0479-1: An update that fixes 13 vulnerabilities is now available. Category: security (important) Bug References: 1020872,1020873,1020875,1020876,1020877,1020878,1020882,1020884,1020885,1020890,1020893,1020894,1020896 CVE References: CVE-2016-8318,CVE-2016-8327,CVE-2017-3238,CVE-2017-3244,CVE-2017-3257,CVE-2017-3258,CVE-2017-3265,CVE-2017-3273,CVE-2017-3291,CVE-2017-3312,CVE-2017-3313,CVE-2017-3317,CVE-2017-3318 Sources used: openSUSE Leap 42.1 (src): mysql-community-server-5.6.35-22.1 This is an autogenerated message for OBS integration: This bug (1020890) was mentioned in https://build.opensuse.org/request/show/476795 42.2 / mysql-community-server openSUSE-SU-2017:0618-1: An update that fixes 13 vulnerabilities is now available. Category: security (important) Bug References: 1020872,1020873,1020875,1020876,1020877,1020878,1020882,1020884,1020885,1020890,1020893,1020894,1020896 CVE References: CVE-2016-8318,CVE-2016-8327,CVE-2017-3238,CVE-2017-3244,CVE-2017-3257,CVE-2017-3258,CVE-2017-3265,CVE-2017-3273,CVE-2017-3291,CVE-2017-3312,CVE-2017-3313,CVE-2017-3317,CVE-2017-3318 Sources used: openSUSE Leap 42.2 (src): mysql-community-server-5.6.35-22.1 mariadb ------- - CVE-2017-3313 was fixed [1] in the latest MariaDB 10.0.30 and MariaDB 10.1.22 [1] https://mariadb.com/kb/en/mariadb/security/ SUSE-SU-2017:1311-1: An update that solves two vulnerabilities and has two fixes is now available. Category: security (important) Bug References: 1020890,1020976,1022428,1034911 CVE References: CVE-2017-3302,CVE-2017-3313 Sources used: SUSE Linux Enterprise Server for SAP 12 (src): mariadb-10.0.30-20.26.1 SUSE Linux Enterprise Server 12-LTSS (src): mariadb-10.0.30-20.26.1 SUSE-SU-2017:1315-1: An update that solves two vulnerabilities and has four fixes is now available. Category: security (important) Bug References: 1020868,1020890,1020976,1022428,1034911,996821 CVE References: CVE-2017-3302,CVE-2017-3313 Sources used: SUSE Linux Enterprise Workstation Extension 12-SP2 (src): mariadb-10.0.30-25.1 SUSE Linux Enterprise Workstation Extension 12-SP1 (src): mariadb-10.0.30-25.1 SUSE Linux Enterprise Software Development Kit 12-SP2 (src): mariadb-10.0.30-25.1 SUSE Linux Enterprise Software Development Kit 12-SP1 (src): mariadb-10.0.30-25.1 SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (src): mariadb-10.0.30-25.1 SUSE Linux Enterprise Server 12-SP2 (src): mariadb-10.0.30-25.1 SUSE Linux Enterprise Server 12-SP1 (src): mariadb-10.0.30-25.1 SUSE Linux Enterprise Desktop 12-SP2 (src): mariadb-10.0.30-25.1 SUSE Linux Enterprise Desktop 12-SP1 (src): mariadb-10.0.30-25.1 openSUSE-SU-2017:1475-1: An update that solves two vulnerabilities and has 5 fixes is now available. Category: security (important) Bug References: 1020868,1020890,1020976,1022428,1034911,1038740,996821 CVE References: CVE-2017-3302,CVE-2017-3313 Sources used: openSUSE Leap 42.2 (src): mariadb-10.0.30-20.4.1 released |