Debian DLA-819-2 : mysql-5.5 version number correction

high Nessus Plugin ID 97087

Synopsis

The remote Debian host is missing a security update.

Description

This is a correction of DLA 819-1 that mentioned that mysql-5.5 5.5.47-0+deb7u2 was corrected. The corrected package version was 5.5.54-0+deb7u2.

For completeness the text from DLA 819-1 is available below with only corrected version information. No other changes.

It has been found that the C client library for MySQL (libmysqlclient.so) has use-after-free vulnerability which can cause crash of applications using that MySQL client.

For Debian 7 'Wheezy', these problems have been fixed in version 5.5.54-0+deb7u2.

We recommend that you upgrade your mysql-5.5 packages.

NOTE: Tenable Network Security has extracted the preceding description block directly from the DLA security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.

Solution

Upgrade the affected packages.

See Also

https://lists.debian.org/debian-lts-announce/2017/02/msg00009.html

https://packages.debian.org/source/wheezy/mysql-5.5

Plugin Details

Severity: High

ID: 97087

File Name: debian_DLA-819.nasl

Version: 3.4

Type: local

Agent: unix

Published: 2/10/2017

Updated: 1/11/2021

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:libmysqlclient-dev, p-cpe:/a:debian:debian_linux:libmysqlclient18, p-cpe:/a:debian:debian_linux:libmysqld-dev, p-cpe:/a:debian:debian_linux:libmysqld-pic, p-cpe:/a:debian:debian_linux:mysql-client, p-cpe:/a:debian:debian_linux:mysql-client-5.5, p-cpe:/a:debian:debian_linux:mysql-common, p-cpe:/a:debian:debian_linux:mysql-server, p-cpe:/a:debian:debian_linux:mysql-server-5.5, p-cpe:/a:debian:debian_linux:mysql-server-core-5.5, p-cpe:/a:debian:debian_linux:mysql-source-5.5, p-cpe:/a:debian:debian_linux:mysql-testsuite-5.5, cpe:/o:debian:debian_linux:7.0

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Patch Publication Date: 2/10/2017