Lucene search

K
slackwareSlackware Linux ProjectSSA-2018-130-01
HistoryMay 10, 2018 - 9:14 p.m.

[slackware-security] mariadb

2018-05-1021:14:32
Slackware Linux Project
www.slackware.com
57

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:N/I:N/A:C

7.7 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

0.003 Low

EPSS

Percentile

70.6%

New mariadb packages are available for Slackware 14.1 and 14.2 to
fix security issues.

Here are the details from the Slackware 14.2 ChangeLog:

patches/packages/mariadb-10.0.35-i586-1_slack14.2.txz: Upgraded.
This update fixes bugs and security issues.
For more information, see:
https://vulners.com/cve/CVE-2018-2782
https://vulners.com/cve/CVE-2018-2784
https://vulners.com/cve/CVE-2018-2787
https://vulners.com/cve/CVE-2018-2766
https://vulners.com/cve/CVE-2018-2755
https://vulners.com/cve/CVE-2018-2819
https://vulners.com/cve/CVE-2018-2817
https://vulners.com/cve/CVE-2018-2761
https://vulners.com/cve/CVE-2018-2781
https://vulners.com/cve/CVE-2018-2771
https://vulners.com/cve/CVE-2018-2813
(* Security fix *)

Where to find the new packages:

Thanks to the friendly folks at the OSU Open Source Lab
(http://osuosl.org) for donating FTP and rsync hosting
to the Slackware project! :-)

Also see the “Get Slack” section on http://slackware.com for
additional mirror sites near you.

Updated package for Slackware 14.1:
ftp://ftp.slackware.com/pub/slackware/slackware-14.1/patches/packages/mariadb-5.5.60-i486-1_slack14.1.txz

Updated package for Slackware x86_64 14.1:
ftp://ftp.slackware.com/pub/slackware/slackware64-14.1/patches/packages/mariadb-5.5.60-x86_64-1_slack14.1.txz

Updated package for Slackware 14.2:
ftp://ftp.slackware.com/pub/slackware/slackware-14.2/patches/packages/mariadb-10.0.35-i586-1_slack14.2.txz

Updated package for Slackware x86_64 14.2:
ftp://ftp.slackware.com/pub/slackware/slackware64-14.2/patches/packages/mariadb-10.0.35-x86_64-1_slack14.2.txz

MD5 signatures:

Slackware 14.1 package:
3b71d2f3d141f91c67a174eb02f3aef2 mariadb-5.5.60-i486-1_slack14.1.txz

Slackware x86_64 14.1 package:
8cd272a56bcad890e7c961d511f70fc6 mariadb-5.5.60-x86_64-1_slack14.1.txz

Slackware 14.2 package:
e7d91844d97f3d02e7b1719ed4023e97 mariadb-10.0.35-i586-1_slack14.2.txz

Slackware x86_64 14.2 package:
1a9d3c18b1b3eb0f48c5b700faf7352e mariadb-10.0.35-x86_64-1_slack14.2.txz

Installation instructions:

Upgrade the package as root:
> upgradepkg mariadb-10.0.35-i586-1_slack14.2.txz

Then, restart the database server:
> sh /etc/rc.d/rc.mysqld restart

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:N/I:N/A:C

7.7 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

0.003 Low

EPSS

Percentile

70.6%