openSUSE Security Update : mysql-community-server (openSUSE-2016-607)

This script is Copyright (C) 2016 Tenable Network Security, Inc.


Synopsis :

The remote openSUSE host is missing a security update.

Description :

This mysql-community-server version update to 5.6.30 fixes the
following issues :

Security issues fixed :

- fixed CVEs (boo#962779, boo#959724): CVE-2016-0705,
CVE-2016-0639, CVE-2015-3194, CVE-2016-0640,
CVE-2016-2047, CVE-2016-0644, CVE-2016-0646,
CVE-2016-0647, CVE-2016-0648, CVE-2016-0649,
CVE-2016-0650, CVE-2016-0665, CVE-2016-0666,
CVE-2016-0641, CVE-2016-0642, CVE-2016-0655,
CVE-2016-0661, CVE-2016-0668, CVE-2016-0643

- changes
http://dev.mysql.com/doc/relnotes/mysql/5.6/en/news-5-6-
30.html
http://dev.mysql.com/doc/relnotes/mysql/5.6/en/news-5-6-
29.html

Bugs fixed :

- don't delete the log data when migration fails

- add 'log-error' and 'secure-file-priv' configuration
options (added via configuration-tweaks.tar.bz2)
[boo#963810]

- add '/etc/my.cnf.d/error_log.conf' that specifies
'log-error = /var/log/mysql/mysqld.log'. If no path is
set, the error log is written to
'/var/lib/mysql/$HOSTNAME.err', which is not picked up
by logrotate.

- add '/etc/my.cnf.d/secure_file_priv.conf' which
specifies that 'LOAD DATA', 'SELECT ... INTO' and 'LOAD
FILE()' will only work with files in the directory
specified by 'secure-file-priv' option
(='/var/lib/mysql-files').

See also :

http://dev.mysql.com/doc/relnotes/mysql/5.6/en/news-5-6-29.html
http://dev.mysql.com/doc/relnotes/mysql/5.6/en/news-5-6-30.html
https://bugzilla.opensuse.org/show_bug.cgi?id=959724
https://bugzilla.opensuse.org/show_bug.cgi?id=962779
https://bugzilla.opensuse.org/show_bug.cgi?id=963810

Solution :

Update the affected mysql-community-server packages.

Risk factor :

Critical / CVSS Base Score : 10.0
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now