openSUSE Security Update : percona-toolkit / xtrabackup (openSUSE-2015-217)

medium Nessus Plugin ID 81761

Synopsis

The remote openSUSE host is missing a security update.

Description

Percona Toolkit and XtraBackup were updated to fix bugs and security issues.

Percona XtraBackup was vulnerable to MITM attack which could allow exfiltration of MySQL configuration information via the
--version-check option. [boo#919298] CVE-2015-1027 lp#1408375.

The openSUSE package has the version check disabled by default.

Percona Toolkit was updated to 2.2.13 :

- Feature lp#1391240: pt-kill added query fingerprint hash to output

- Fixed lp#1402668: pt-mysql-summary fails on cluster in Donor/Desynced status

- Fixed lp#1396870: pt-online-schema-change CTRL+C leaves terminal in inconsistent state

- Fixed lp#1396868: pt-online-schema-change --ask-pass option error

- Fixed lp#1266869: pt-stalk fails to start if $HOME environment variable is not set

- Fixed lp#1019479: pt-table-checksum does not work with sql_mode ONLY_FULL_GROUP_BY

- Fixed lp#1394934: pt-table-checksum error in debug mode

- Fixed lp#1321297: pt-table-checksum reports diffs on timestamp columns in 5.5 vs 5.6

- Fixed lp#1399789: pt-table-checksum fails to find pxc nodes when wsrep_node_incoming_address is set to AUTO

- Fixed lp#1388870: pt-table-checksum has some errors with different time zones

- Fixed lp#1408375: vulnerable to MITM attack which would allow exfiltration of MySQL configuration information via --version-check [boo#919298] [CVE-2015-1027]

- Fixed lp#1404298: missing MySQL5.7 test files for pt-table-checksum

- Fixed lp#1403900: added sandbox and fixed sakila test db for 5.7

Percona XtraBackup was updated to version 2.2.9 :

- xtrabackup_galera_info file isn't overwritten during the Galera auto-recovery. lp#1418584.

- Percona XtraBackup now sets the maximum supported session value for lock_wait_timeout variable to prevent unnecessary timeouts when the global value is changed from the default. lp#1410339.

- New option --backup-locks, enabled by default, has been implemented to control if backup locks will be used even if they are supported by the server. To disable backup locks innobackupex should be run with innobackupex
--no-backup-locks option. lp#1418820.

Solution

Update the affected percona-toolkit / xtrabackup packages.

See Also

https://bugzilla.opensuse.org/show_bug.cgi?id=919298

Plugin Details

Severity: Medium

ID: 81761

File Name: openSUSE-2015-217.nasl

Version: 1.5

Type: local

Agent: unix

Published: 3/12/2015

Updated: 1/19/2021

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.4

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS v3

Risk Factor: Medium

Base Score: 5.9

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Vulnerability Information

CPE: p-cpe:/a:novell:opensuse:percona-toolkit, p-cpe:/a:novell:opensuse:xtrabackup, p-cpe:/a:novell:opensuse:xtrabackup-debuginfo, p-cpe:/a:novell:opensuse:xtrabackup-debugsource, p-cpe:/a:novell:opensuse:xtrabackup-test, cpe:/o:novell:opensuse:13.1, cpe:/o:novell:opensuse:13.2

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Patch Publication Date: 3/3/2015

Reference Information

CVE: CVE-2015-1027