openSUSE Security Update : MariaDB (openSUSE-2015-479) (BACKRONYM) (Logjam)

High Nessus Plugin ID 84658

Synopsis

The remote openSUSE host is missing a security update.

Description

MariaDB was updated to its current minor version, fixing bugs and security issues.

These updates include a fix for Logjam (CVE-2015-4000), making MariaDB work with client software that no longer allows short DH groups over SSL, as e.g. our current openssl packages.

On openSUSE 13.1, MariaDB was updated to 5.5.44.

On openSUSE 13.2, MariaDB was updated from 10.0.13 to 10.0.20.

Please read the release notes of MariaDB https://mariadb.com/kb/en/mariadb/mariadb-10020-release-notes/ https://mariadb.com/kb/en/mariadb/mariadb-10019-release-notes/ https://mariadb.com/kb/en/mariadb/mariadb-10018-release-notes/ https://mariadb.com/kb/en/mariadb/mariadb-10017-release-notes/ https://mariadb.com/kb/en/mariadb/mariadb-10016-release-notes/ https://mariadb.com/kb/en/mariadb/mariadb-10015-release-notes/ https://mariadb.com/kb/en/mariadb/mariadb-10014-release-notes/ for more information.

Solution

Update the affected MariaDB packages.

See Also

https://bugzilla.opensuse.org/show_bug.cgi?id=859345

https://bugzilla.opensuse.org/show_bug.cgi?id=914370

https://bugzilla.opensuse.org/show_bug.cgi?id=924663

https://bugzilla.opensuse.org/show_bug.cgi?id=934789

https://bugzilla.opensuse.org/show_bug.cgi?id=936407

https://bugzilla.opensuse.org/show_bug.cgi?id=936408

https://bugzilla.opensuse.org/show_bug.cgi?id=936409

https://mariadb.com/kb/en/library/mariadb-10014-release-notes/

https://mariadb.com/kb/en/library/mariadb-10015-release-notes/

https://mariadb.com/kb/en/library/mariadb-10016-release-notes/

https://mariadb.com/kb/en/library/mariadb-10017-release-notes/

https://mariadb.com/kb/en/library/mariadb-10018-release-notes/

https://mariadb.com/kb/en/library/mariadb-10019-release-notes/

https://mariadb.com/kb/en/library/mariadb-10020-release-notes/

Plugin Details

Severity: High

ID: 84658

File Name: openSUSE-2015-479.nasl

Version: 1.10

Type: local

Agent: unix

Published: 2015/07/13

Updated: 2018/12/19

Dependencies: 12634

Risk Information

Risk Factor: High

CVSS v2.0

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS v3.0

Base Score: 5.9

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Vulnerability Information

CPE: p-cpe:/a:novell:opensuse:libmysqlclient-devel, p-cpe:/a:novell:opensuse:libmysqlclient18, p-cpe:/a:novell:opensuse:libmysqlclient18-32bit, p-cpe:/a:novell:opensuse:libmysqlclient18-debuginfo, p-cpe:/a:novell:opensuse:libmysqlclient18-debuginfo-32bit, p-cpe:/a:novell:opensuse:libmysqlclient_r18, p-cpe:/a:novell:opensuse:libmysqlclient_r18-32bit, p-cpe:/a:novell:opensuse:libmysqld-devel, p-cpe:/a:novell:opensuse:libmysqld18, p-cpe:/a:novell:opensuse:libmysqld18-debuginfo, p-cpe:/a:novell:opensuse:mariadb, p-cpe:/a:novell:opensuse:mariadb-bench, p-cpe:/a:novell:opensuse:mariadb-bench-debuginfo, p-cpe:/a:novell:opensuse:mariadb-client, p-cpe:/a:novell:opensuse:mariadb-client-debuginfo, p-cpe:/a:novell:opensuse:mariadb-debuginfo, p-cpe:/a:novell:opensuse:mariadb-debugsource, p-cpe:/a:novell:opensuse:mariadb-errormessages, p-cpe:/a:novell:opensuse:mariadb-test, p-cpe:/a:novell:opensuse:mariadb-test-debuginfo, p-cpe:/a:novell:opensuse:mariadb-tools, p-cpe:/a:novell:opensuse:mariadb-tools-debuginfo, cpe:/o:novell:opensuse:13.1, cpe:/o:novell:opensuse:13.2

Required KB Items: Host/local_checks_enabled, Host/SuSE/release, Host/SuSE/rpm-list, Host/cpu

Patch Publication Date: 2015/07/01

Reference Information

CVE: CVE-2014-6464, CVE-2014-6469, CVE-2014-6491, CVE-2014-6494, CVE-2014-6496, CVE-2014-6500, CVE-2014-6507, CVE-2014-6555, CVE-2014-6559, CVE-2014-6568, CVE-2014-8964, CVE-2015-0374, CVE-2015-0381, CVE-2015-0382, CVE-2015-0411, CVE-2015-0432, CVE-2015-0433, CVE-2015-0441, CVE-2015-0499, CVE-2015-0501, CVE-2015-0505, CVE-2015-2325, CVE-2015-2326, CVE-2015-2568, CVE-2015-2571, CVE-2015-2573, CVE-2015-3152, CVE-2015-4000