suse-su-2019:0555-1
Vulnerability from csaf_suse
Published
2019-03-06 09:55
Modified
2019-03-06 09:55
Summary
Security update for mariadb
Notes
Title of the patch
Security update for mariadb
Description of the patch
This update for mariadb to version 10.2.22 fixes the following issues:
Security issues fixed:
- CVE-2019-2510: Fixed a vulnerability which can lead to MySQL compromise and lead to Denial of Service (bsc#1122198).
- CVE-2019-2537: Fixed a vulnerability which can lead to MySQL compromise and lead to Denial of Service (bsc#1122198).
- CVE-2018-3284: Fixed InnoDB unspecified vulnerability (CPU Oct 2018) (bsc#1112377)
- CVE-2018-3282: Server Storage Engines unspecified vulnerability (CPU Oct 2018) (bsc#1112432)
- CVE-2018-3277: Fixed InnoDB unspecified vulnerability (CPU Oct 2018) (bsc#1112391)
- CVE-2018-3251: InnoDB unspecified vulnerability (CPU Oct 2018) (bsc#1112397)
- CVE-2018-3200: Fixed InnoDB unspecified vulnerability (CPU Oct 2018) (bsc#1112404)
- CVE-2018-3185: Fixed InnoDB unspecified vulnerability (CPU Oct 2018) (bsc#1112384)
- CVE-2018-3174: Client programs unspecified vulnerability (CPU Oct 2018) (bsc#1112368)
- CVE-2018-3173: Fixed InnoDB unspecified vulnerability (CPU Oct 2018) (bsc#1112386)
- CVE-2018-3162: Fixed InnoDB unspecified vulnerability (CPU Oct 2018) (bsc#1112415)
- CVE-2018-3156: InnoDB unspecified vulnerability (CPU Oct 2018) (bsc#1112417)
- CVE-2018-3143: InnoDB unspecified vulnerability (CPU Oct 2018) (bsc#1112421)
- CVE-2018-3066: Unspecified vulnerability in the MySQL Server component of Oracle MySQL (subcomponent Server Options). (bsc#1101678)
- CVE-2018-3064: InnoDB unspecified vulnerability (CPU Jul 2018) (bsc#1103342)
- CVE-2018-3063: Unspecified vulnerability in the MySQL Server component of Oracle MySQL (subcomponent Server Security Privileges). (bsc#1101677)
- CVE-2018-3058: Unspecified vulnerability in the MySQL Server component of Oracle MySQL (subcomponent MyISAM). (bsc#1101676)
- CVE-2016-9843: Big-endian out-of-bounds pointer (bsc#1013882)
Non-security issues fixed:
- Fixed an issue where mysl_install_db fails due to incorrect basedir (bsc#1127027).
- Fixed an issue where the lograte was not working (bsc#1112767).
- Backport Information Schema CHECK_CONSTRAINTS Table.
- Maximum value of table_definition_cache is now 2097152.
- InnoDB ALTER TABLE fixes.
- Galera crash recovery fixes.
- Encryption fixes.
- Remove xtrabackup dependency as MariaDB ships a build in mariabackup so xtrabackup is not needed (bsc#1122475).
- Maria DB testsuite - test main.plugin_auth failed (bsc#1111859)
- Maria DB testsuite - test encryption.second_plugin-12863 failed (bsc#1111858)
- Remove PerconaFT from the package as it has AGPL licence (bsc#1118754)
- remove PerconaFT from the package as it has AGPL licence (bsc#1118754)
- Database corruption after renaming a prefix-indexed column (bsc#1120041)
Release notes and changelog:
- https://mariadb.com/kb/en/library/mariadb-10222-release-notes
- https://mariadb.com/kb/en/library/mariadb-10222-changelog/
Patchnames
SUSE-2019-555,SUSE-SLE-Module-Development-Tools-OBS-15-2019-555,SUSE-SLE-Module-Server-Applications-15-2019-555
Terms of use
CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
{ "document": { "aggregate_severity": { "namespace": "https://www.suse.com/support/security/rating/", "text": "important" }, "category": "csaf_security_advisory", "csaf_version": "2.0", "distribution": { "text": "Copyright 2024 SUSE LLC. All rights reserved.", "tlp": { "label": "WHITE", "url": "https://www.first.org/tlp/" } }, "lang": "en", "notes": [ { "category": "summary", "text": "Security update for mariadb", "title": "Title of the patch" }, { "category": "description", "text": "This update for mariadb to version 10.2.22 fixes the following issues:\n\nSecurity issues fixed:\n\n- CVE-2019-2510: Fixed a vulnerability which can lead to MySQL compromise and lead to Denial of Service (bsc#1122198). \n- CVE-2019-2537: Fixed a vulnerability which can lead to MySQL compromise and lead to Denial of Service (bsc#1122198).\n- CVE-2018-3284: Fixed InnoDB unspecified vulnerability (CPU Oct 2018) (bsc#1112377)\n- CVE-2018-3282: Server Storage Engines unspecified vulnerability (CPU Oct 2018) (bsc#1112432)\n- CVE-2018-3277: Fixed InnoDB unspecified vulnerability (CPU Oct 2018) (bsc#1112391)\n- CVE-2018-3251: InnoDB unspecified vulnerability (CPU Oct 2018) (bsc#1112397)\n- CVE-2018-3200: Fixed InnoDB unspecified vulnerability (CPU Oct 2018) (bsc#1112404)\n- CVE-2018-3185: Fixed InnoDB unspecified vulnerability (CPU Oct 2018) (bsc#1112384)\n- CVE-2018-3174: Client programs unspecified vulnerability (CPU Oct 2018) (bsc#1112368)\n- CVE-2018-3173: Fixed InnoDB unspecified vulnerability (CPU Oct 2018) (bsc#1112386)\n- CVE-2018-3162: Fixed InnoDB unspecified vulnerability (CPU Oct 2018) (bsc#1112415)\n- CVE-2018-3156: InnoDB unspecified vulnerability (CPU Oct 2018) (bsc#1112417)\n- CVE-2018-3143: InnoDB unspecified vulnerability (CPU Oct 2018) (bsc#1112421)\n- CVE-2018-3066: Unspecified vulnerability in the MySQL Server component of Oracle MySQL (subcomponent Server Options). (bsc#1101678)\n- CVE-2018-3064: InnoDB unspecified vulnerability (CPU Jul 2018) (bsc#1103342)\n- CVE-2018-3063: Unspecified vulnerability in the MySQL Server component of Oracle MySQL (subcomponent Server Security Privileges). (bsc#1101677)\n- CVE-2018-3058: Unspecified vulnerability in the MySQL Server component of Oracle MySQL (subcomponent MyISAM). (bsc#1101676)\n- CVE-2016-9843: Big-endian out-of-bounds pointer (bsc#1013882)\n\nNon-security issues fixed:\n\n- Fixed an issue where mysl_install_db fails due to incorrect basedir (bsc#1127027).\n- Fixed an issue where the lograte was not working (bsc#1112767).\n- Backport Information Schema CHECK_CONSTRAINTS Table.\n- Maximum value of table_definition_cache is now 2097152.\n- InnoDB ALTER TABLE fixes.\n- Galera crash recovery fixes.\n- Encryption fixes.\n- Remove xtrabackup dependency as MariaDB ships a build in mariabackup so xtrabackup is not needed (bsc#1122475).\n- Maria DB testsuite - test main.plugin_auth failed (bsc#1111859)\n- Maria DB testsuite - test encryption.second_plugin-12863 failed (bsc#1111858)\n- Remove PerconaFT from the package as it has AGPL licence (bsc#1118754)\n- remove PerconaFT from the package as it has AGPL licence (bsc#1118754)\n- Database corruption after renaming a prefix-indexed column (bsc#1120041)\n\n\nRelease notes and changelog:\n\n- https://mariadb.com/kb/en/library/mariadb-10222-release-notes\n- https://mariadb.com/kb/en/library/mariadb-10222-changelog/\n", "title": "Description of the patch" }, { "category": "details", "text": "SUSE-2019-555,SUSE-SLE-Module-Development-Tools-OBS-15-2019-555,SUSE-SLE-Module-Server-Applications-15-2019-555", "title": "Patchnames" }, { "category": "legal_disclaimer", "text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).", "title": "Terms of use" } ], "publisher": { "category": "vendor", "contact_details": "https://www.suse.com/support/security/contact/", "name": "SUSE Product Security Team", "namespace": "https://www.suse.com/" }, "references": [ { "category": "external", "summary": "SUSE ratings", "url": "https://www.suse.com/support/security/rating/" }, { "category": "self", "summary": "URL of this CSAF notice", "url": "https://ftp.suse.com/pub/projects/security/csaf/suse-su-2019_0555-1.json" }, { "category": "self", "summary": "URL for SUSE-SU-2019:0555-1", "url": "https://www.suse.com/support/update/announcement/2019/suse-su-20190555-1/" }, { "category": "self", "summary": "E-Mail link for SUSE-SU-2019:0555-1", "url": "https://www.suse.com/support/update/announcement/2019/suse-su-20190555-1.html" }, { "category": "self", "summary": "SUSE Bug 1013882", "url": "https://bugzilla.suse.com/1013882" }, { "category": "self", "summary": "SUSE Bug 1101676", "url": "https://bugzilla.suse.com/1101676" }, { "category": "self", "summary": "SUSE Bug 1101677", "url": "https://bugzilla.suse.com/1101677" }, { "category": "self", "summary": "SUSE Bug 1101678", "url": "https://bugzilla.suse.com/1101678" }, { "category": "self", "summary": "SUSE Bug 1103342", "url": "https://bugzilla.suse.com/1103342" }, { "category": "self", "summary": "SUSE Bug 1111858", "url": "https://bugzilla.suse.com/1111858" }, { "category": "self", "summary": "SUSE Bug 1111859", "url": "https://bugzilla.suse.com/1111859" }, { "category": "self", "summary": "SUSE Bug 1112368", "url": "https://bugzilla.suse.com/1112368" }, { "category": "self", "summary": "SUSE Bug 1112377", "url": "https://bugzilla.suse.com/1112377" }, { "category": "self", "summary": "SUSE Bug 1112384", "url": "https://bugzilla.suse.com/1112384" }, { "category": "self", "summary": "SUSE Bug 1112386", "url": "https://bugzilla.suse.com/1112386" }, { "category": "self", "summary": "SUSE Bug 1112391", "url": "https://bugzilla.suse.com/1112391" }, { "category": "self", "summary": "SUSE Bug 1112397", "url": "https://bugzilla.suse.com/1112397" }, { "category": "self", "summary": "SUSE Bug 1112404", "url": "https://bugzilla.suse.com/1112404" }, { "category": "self", "summary": "SUSE Bug 1112415", "url": "https://bugzilla.suse.com/1112415" }, { "category": "self", "summary": "SUSE Bug 1112417", "url": "https://bugzilla.suse.com/1112417" }, { "category": "self", "summary": "SUSE Bug 1112421", "url": "https://bugzilla.suse.com/1112421" }, { "category": "self", "summary": "SUSE Bug 1112432", "url": "https://bugzilla.suse.com/1112432" }, { "category": "self", "summary": "SUSE Bug 1112767", "url": "https://bugzilla.suse.com/1112767" }, { "category": "self", "summary": "SUSE Bug 1116686", "url": "https://bugzilla.suse.com/1116686" }, { "category": "self", "summary": "SUSE Bug 1118754", "url": "https://bugzilla.suse.com/1118754" }, { "category": "self", "summary": "SUSE Bug 1120041", "url": "https://bugzilla.suse.com/1120041" }, { "category": "self", "summary": "SUSE Bug 1122198", "url": "https://bugzilla.suse.com/1122198" }, { "category": "self", "summary": "SUSE Bug 1122475", "url": "https://bugzilla.suse.com/1122475" }, { "category": "self", "summary": "SUSE Bug 1127027", "url": "https://bugzilla.suse.com/1127027" }, { "category": "self", "summary": "SUSE CVE CVE-2016-9843 page", "url": "https://www.suse.com/security/cve/CVE-2016-9843/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-3058 page", "url": "https://www.suse.com/security/cve/CVE-2018-3058/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-3060 page", "url": "https://www.suse.com/security/cve/CVE-2018-3060/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-3063 page", "url": "https://www.suse.com/security/cve/CVE-2018-3063/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-3064 page", "url": "https://www.suse.com/security/cve/CVE-2018-3064/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-3066 page", "url": "https://www.suse.com/security/cve/CVE-2018-3066/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-3143 page", "url": "https://www.suse.com/security/cve/CVE-2018-3143/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-3156 page", "url": "https://www.suse.com/security/cve/CVE-2018-3156/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-3162 page", "url": "https://www.suse.com/security/cve/CVE-2018-3162/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-3173 page", "url": "https://www.suse.com/security/cve/CVE-2018-3173/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-3174 page", "url": "https://www.suse.com/security/cve/CVE-2018-3174/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-3185 page", "url": "https://www.suse.com/security/cve/CVE-2018-3185/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-3200 page", "url": "https://www.suse.com/security/cve/CVE-2018-3200/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-3251 page", "url": "https://www.suse.com/security/cve/CVE-2018-3251/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-3277 page", "url": "https://www.suse.com/security/cve/CVE-2018-3277/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-3282 page", "url": "https://www.suse.com/security/cve/CVE-2018-3282/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-3284 page", "url": "https://www.suse.com/security/cve/CVE-2018-3284/" }, { "category": "self", "summary": "SUSE CVE CVE-2019-2510 page", "url": "https://www.suse.com/security/cve/CVE-2019-2510/" }, { "category": "self", "summary": "SUSE CVE CVE-2019-2537 page", "url": "https://www.suse.com/security/cve/CVE-2019-2537/" } ], "title": "Security update for mariadb", "tracking": { "current_release_date": "2019-03-06T09:55:52Z", "generator": { "date": "2019-03-06T09:55:52Z", "engine": { "name": "cve-database.git:bin/generate-csaf.pl", "version": "1" } }, "id": "SUSE-SU-2019:0555-1", "initial_release_date": "2019-03-06T09:55:52Z", "revision_history": [ { "date": "2019-03-06T09:55:52Z", "number": "1", "summary": "Current version" } ], "status": "final", "version": "1" } }, "product_tree": { "branches": [ { "branches": [ { "branches": [ { "category": "product_version", "name": "libmysqld-devel-10.2.22-3.14.1.aarch64", "product": { "name": "libmysqld-devel-10.2.22-3.14.1.aarch64", "product_id": "libmysqld-devel-10.2.22-3.14.1.aarch64" } }, { "category": "product_version", "name": "libmysqld19-10.2.22-3.14.1.aarch64", "product": { "name": "libmysqld19-10.2.22-3.14.1.aarch64", "product_id": "libmysqld19-10.2.22-3.14.1.aarch64" } }, { "category": "product_version", "name": "mariadb-10.2.22-3.14.1.aarch64", "product": { "name": "mariadb-10.2.22-3.14.1.aarch64", "product_id": "mariadb-10.2.22-3.14.1.aarch64" } }, { "category": "product_version", "name": "mariadb-bench-10.2.22-3.14.1.aarch64", "product": { "name": "mariadb-bench-10.2.22-3.14.1.aarch64", "product_id": "mariadb-bench-10.2.22-3.14.1.aarch64" } }, { "category": "product_version", "name": "mariadb-client-10.2.22-3.14.1.aarch64", "product": { "name": "mariadb-client-10.2.22-3.14.1.aarch64", "product_id": "mariadb-client-10.2.22-3.14.1.aarch64" } }, { "category": "product_version", "name": "mariadb-galera-10.2.22-3.14.1.aarch64", "product": { "name": "mariadb-galera-10.2.22-3.14.1.aarch64", "product_id": "mariadb-galera-10.2.22-3.14.1.aarch64" } }, { "category": "product_version", "name": "mariadb-test-10.2.22-3.14.1.aarch64", "product": { "name": "mariadb-test-10.2.22-3.14.1.aarch64", "product_id": "mariadb-test-10.2.22-3.14.1.aarch64" } }, { "category": "product_version", "name": "mariadb-tools-10.2.22-3.14.1.aarch64", "product": { "name": "mariadb-tools-10.2.22-3.14.1.aarch64", "product_id": "mariadb-tools-10.2.22-3.14.1.aarch64" } } ], "category": "architecture", "name": "aarch64" }, { "branches": [ { "category": "product_version", "name": "libmysqld-devel-10.2.22-3.14.1.i586", "product": { "name": "libmysqld-devel-10.2.22-3.14.1.i586", "product_id": "libmysqld-devel-10.2.22-3.14.1.i586" } }, { "category": "product_version", "name": "libmysqld19-10.2.22-3.14.1.i586", "product": { "name": "libmysqld19-10.2.22-3.14.1.i586", "product_id": "libmysqld19-10.2.22-3.14.1.i586" } }, { "category": "product_version", "name": "mariadb-10.2.22-3.14.1.i586", "product": { "name": "mariadb-10.2.22-3.14.1.i586", "product_id": "mariadb-10.2.22-3.14.1.i586" } }, { "category": "product_version", "name": "mariadb-bench-10.2.22-3.14.1.i586", "product": { "name": "mariadb-bench-10.2.22-3.14.1.i586", "product_id": "mariadb-bench-10.2.22-3.14.1.i586" } }, { "category": "product_version", "name": "mariadb-client-10.2.22-3.14.1.i586", "product": { "name": "mariadb-client-10.2.22-3.14.1.i586", "product_id": "mariadb-client-10.2.22-3.14.1.i586" } }, { "category": "product_version", "name": "mariadb-galera-10.2.22-3.14.1.i586", "product": { "name": "mariadb-galera-10.2.22-3.14.1.i586", "product_id": "mariadb-galera-10.2.22-3.14.1.i586" } }, { "category": "product_version", "name": "mariadb-test-10.2.22-3.14.1.i586", "product": { "name": "mariadb-test-10.2.22-3.14.1.i586", "product_id": "mariadb-test-10.2.22-3.14.1.i586" } }, { "category": "product_version", "name": "mariadb-tools-10.2.22-3.14.1.i586", "product": { "name": "mariadb-tools-10.2.22-3.14.1.i586", "product_id": "mariadb-tools-10.2.22-3.14.1.i586" } } ], "category": "architecture", "name": "i586" }, { "branches": [ { "category": "product_version", "name": "mariadb-errormessages-10.2.22-3.14.1.noarch", "product": { "name": "mariadb-errormessages-10.2.22-3.14.1.noarch", "product_id": "mariadb-errormessages-10.2.22-3.14.1.noarch" } } ], "category": "architecture", "name": "noarch" }, { "branches": [ { "category": "product_version", "name": "libmysqld-devel-10.2.22-3.14.1.ppc64le", "product": { "name": "libmysqld-devel-10.2.22-3.14.1.ppc64le", "product_id": "libmysqld-devel-10.2.22-3.14.1.ppc64le" } }, { "category": "product_version", "name": "libmysqld19-10.2.22-3.14.1.ppc64le", "product": { "name": "libmysqld19-10.2.22-3.14.1.ppc64le", "product_id": "libmysqld19-10.2.22-3.14.1.ppc64le" } }, { "category": "product_version", "name": "mariadb-10.2.22-3.14.1.ppc64le", "product": { "name": "mariadb-10.2.22-3.14.1.ppc64le", "product_id": "mariadb-10.2.22-3.14.1.ppc64le" } }, { "category": "product_version", "name": "mariadb-bench-10.2.22-3.14.1.ppc64le", "product": { "name": "mariadb-bench-10.2.22-3.14.1.ppc64le", "product_id": "mariadb-bench-10.2.22-3.14.1.ppc64le" } }, { "category": "product_version", "name": "mariadb-client-10.2.22-3.14.1.ppc64le", "product": { "name": "mariadb-client-10.2.22-3.14.1.ppc64le", "product_id": "mariadb-client-10.2.22-3.14.1.ppc64le" } }, { "category": "product_version", "name": "mariadb-galera-10.2.22-3.14.1.ppc64le", "product": { "name": "mariadb-galera-10.2.22-3.14.1.ppc64le", "product_id": "mariadb-galera-10.2.22-3.14.1.ppc64le" } }, { "category": "product_version", "name": "mariadb-test-10.2.22-3.14.1.ppc64le", "product": { "name": "mariadb-test-10.2.22-3.14.1.ppc64le", "product_id": "mariadb-test-10.2.22-3.14.1.ppc64le" } }, { "category": "product_version", "name": "mariadb-tools-10.2.22-3.14.1.ppc64le", "product": { "name": "mariadb-tools-10.2.22-3.14.1.ppc64le", "product_id": "mariadb-tools-10.2.22-3.14.1.ppc64le" } } ], "category": "architecture", "name": "ppc64le" }, { "branches": [ { "category": "product_version", "name": "libmysqld-devel-10.2.22-3.14.1.s390x", "product": { "name": "libmysqld-devel-10.2.22-3.14.1.s390x", "product_id": "libmysqld-devel-10.2.22-3.14.1.s390x" } }, { "category": "product_version", "name": "libmysqld19-10.2.22-3.14.1.s390x", "product": { "name": "libmysqld19-10.2.22-3.14.1.s390x", "product_id": "libmysqld19-10.2.22-3.14.1.s390x" } }, { "category": "product_version", "name": "mariadb-10.2.22-3.14.1.s390x", "product": { "name": "mariadb-10.2.22-3.14.1.s390x", "product_id": "mariadb-10.2.22-3.14.1.s390x" } }, { "category": "product_version", "name": "mariadb-bench-10.2.22-3.14.1.s390x", "product": { "name": "mariadb-bench-10.2.22-3.14.1.s390x", "product_id": "mariadb-bench-10.2.22-3.14.1.s390x" } }, { "category": "product_version", "name": "mariadb-client-10.2.22-3.14.1.s390x", "product": { "name": "mariadb-client-10.2.22-3.14.1.s390x", "product_id": "mariadb-client-10.2.22-3.14.1.s390x" } }, { "category": "product_version", "name": "mariadb-galera-10.2.22-3.14.1.s390x", "product": { "name": "mariadb-galera-10.2.22-3.14.1.s390x", "product_id": "mariadb-galera-10.2.22-3.14.1.s390x" } }, { "category": "product_version", "name": "mariadb-test-10.2.22-3.14.1.s390x", "product": { "name": "mariadb-test-10.2.22-3.14.1.s390x", "product_id": "mariadb-test-10.2.22-3.14.1.s390x" } }, { "category": "product_version", "name": "mariadb-tools-10.2.22-3.14.1.s390x", "product": { "name": "mariadb-tools-10.2.22-3.14.1.s390x", "product_id": "mariadb-tools-10.2.22-3.14.1.s390x" } } ], "category": "architecture", "name": "s390x" }, { "branches": [ { "category": "product_version", "name": "libmysqld-devel-10.2.22-3.14.1.x86_64", "product": { "name": "libmysqld-devel-10.2.22-3.14.1.x86_64", "product_id": "libmysqld-devel-10.2.22-3.14.1.x86_64" } }, { "category": "product_version", "name": "libmysqld19-10.2.22-3.14.1.x86_64", "product": { "name": "libmysqld19-10.2.22-3.14.1.x86_64", "product_id": "libmysqld19-10.2.22-3.14.1.x86_64" } }, { "category": "product_version", "name": "mariadb-10.2.22-3.14.1.x86_64", "product": { "name": "mariadb-10.2.22-3.14.1.x86_64", "product_id": "mariadb-10.2.22-3.14.1.x86_64" } }, { "category": "product_version", "name": "mariadb-bench-10.2.22-3.14.1.x86_64", "product": { "name": "mariadb-bench-10.2.22-3.14.1.x86_64", "product_id": "mariadb-bench-10.2.22-3.14.1.x86_64" } }, { "category": "product_version", "name": "mariadb-client-10.2.22-3.14.1.x86_64", "product": { "name": "mariadb-client-10.2.22-3.14.1.x86_64", "product_id": "mariadb-client-10.2.22-3.14.1.x86_64" } }, { "category": "product_version", "name": "mariadb-galera-10.2.22-3.14.1.x86_64", "product": { "name": "mariadb-galera-10.2.22-3.14.1.x86_64", "product_id": "mariadb-galera-10.2.22-3.14.1.x86_64" } }, { "category": "product_version", "name": "mariadb-test-10.2.22-3.14.1.x86_64", "product": { "name": "mariadb-test-10.2.22-3.14.1.x86_64", "product_id": "mariadb-test-10.2.22-3.14.1.x86_64" } }, { "category": "product_version", "name": "mariadb-tools-10.2.22-3.14.1.x86_64", "product": { "name": "mariadb-tools-10.2.22-3.14.1.x86_64", "product_id": "mariadb-tools-10.2.22-3.14.1.x86_64" } } ], "category": "architecture", "name": "x86_64" }, { "branches": [ { "category": "product_name", "name": "SUSE Linux Enterprise Module for Server Applications 15", "product": { "name": "SUSE Linux Enterprise Module for Server Applications 15", "product_id": "SUSE Linux Enterprise Module for Server Applications 15", "product_identification_helper": { "cpe": "cpe:/o:suse:sle-module-server-applications:15" } } } ], "category": "product_family", "name": "SUSE Linux Enterprise" } ], "category": "vendor", "name": "SUSE" } ], "relationships": [ { "category": "default_component_of", "full_product_name": { "name": "libmysqld-devel-10.2.22-3.14.1.aarch64 as component of SUSE Linux Enterprise Module for Server Applications 15", "product_id": "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64" }, "product_reference": "libmysqld-devel-10.2.22-3.14.1.aarch64", "relates_to_product_reference": "SUSE Linux Enterprise Module for Server Applications 15" }, { "category": "default_component_of", "full_product_name": { "name": "libmysqld-devel-10.2.22-3.14.1.ppc64le as component of SUSE Linux Enterprise Module for Server Applications 15", "product_id": "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le" }, "product_reference": "libmysqld-devel-10.2.22-3.14.1.ppc64le", "relates_to_product_reference": "SUSE Linux Enterprise Module for Server Applications 15" }, { "category": "default_component_of", "full_product_name": { "name": "libmysqld-devel-10.2.22-3.14.1.s390x as component of SUSE Linux Enterprise Module for Server Applications 15", "product_id": "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x" }, "product_reference": "libmysqld-devel-10.2.22-3.14.1.s390x", "relates_to_product_reference": "SUSE Linux Enterprise Module for Server Applications 15" }, { "category": "default_component_of", "full_product_name": { "name": "libmysqld-devel-10.2.22-3.14.1.x86_64 as component of SUSE Linux Enterprise Module for Server Applications 15", "product_id": "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64" }, "product_reference": "libmysqld-devel-10.2.22-3.14.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Module for Server Applications 15" }, { "category": "default_component_of", "full_product_name": { "name": "libmysqld19-10.2.22-3.14.1.aarch64 as component of SUSE Linux Enterprise Module for Server Applications 15", "product_id": "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64" }, "product_reference": "libmysqld19-10.2.22-3.14.1.aarch64", "relates_to_product_reference": "SUSE Linux Enterprise Module for Server Applications 15" }, { "category": "default_component_of", "full_product_name": { "name": "libmysqld19-10.2.22-3.14.1.ppc64le as component of SUSE Linux Enterprise Module for Server Applications 15", "product_id": "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le" }, "product_reference": "libmysqld19-10.2.22-3.14.1.ppc64le", "relates_to_product_reference": "SUSE Linux Enterprise Module for Server Applications 15" }, { "category": "default_component_of", "full_product_name": { "name": "libmysqld19-10.2.22-3.14.1.s390x as component of SUSE Linux Enterprise Module for Server Applications 15", "product_id": "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x" }, "product_reference": "libmysqld19-10.2.22-3.14.1.s390x", "relates_to_product_reference": "SUSE Linux Enterprise Module for Server Applications 15" }, { "category": "default_component_of", "full_product_name": { "name": "libmysqld19-10.2.22-3.14.1.x86_64 as component of SUSE Linux Enterprise Module for Server Applications 15", "product_id": "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64" }, "product_reference": "libmysqld19-10.2.22-3.14.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Module for Server Applications 15" }, { "category": "default_component_of", "full_product_name": { "name": "mariadb-10.2.22-3.14.1.aarch64 as component of SUSE Linux Enterprise Module for Server Applications 15", "product_id": "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64" }, "product_reference": "mariadb-10.2.22-3.14.1.aarch64", "relates_to_product_reference": "SUSE Linux Enterprise Module for Server Applications 15" }, { "category": "default_component_of", "full_product_name": { "name": "mariadb-10.2.22-3.14.1.ppc64le as component of SUSE Linux Enterprise Module for Server Applications 15", "product_id": "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le" }, "product_reference": "mariadb-10.2.22-3.14.1.ppc64le", "relates_to_product_reference": "SUSE Linux Enterprise Module for Server Applications 15" }, { "category": "default_component_of", "full_product_name": { "name": "mariadb-10.2.22-3.14.1.s390x as component of SUSE Linux Enterprise Module for Server Applications 15", "product_id": "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x" }, "product_reference": "mariadb-10.2.22-3.14.1.s390x", "relates_to_product_reference": "SUSE Linux Enterprise Module for Server Applications 15" }, { "category": "default_component_of", "full_product_name": { "name": "mariadb-10.2.22-3.14.1.x86_64 as component of SUSE Linux Enterprise Module for Server Applications 15", "product_id": "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64" }, "product_reference": "mariadb-10.2.22-3.14.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Module for Server Applications 15" }, { "category": "default_component_of", "full_product_name": { "name": "mariadb-client-10.2.22-3.14.1.aarch64 as component of SUSE Linux Enterprise Module for Server Applications 15", "product_id": "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64" }, "product_reference": "mariadb-client-10.2.22-3.14.1.aarch64", "relates_to_product_reference": "SUSE Linux Enterprise Module for Server Applications 15" }, { "category": "default_component_of", "full_product_name": { "name": "mariadb-client-10.2.22-3.14.1.ppc64le as component of SUSE Linux Enterprise Module for Server Applications 15", "product_id": "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le" }, "product_reference": "mariadb-client-10.2.22-3.14.1.ppc64le", "relates_to_product_reference": "SUSE Linux Enterprise Module for Server Applications 15" }, { "category": "default_component_of", "full_product_name": { "name": "mariadb-client-10.2.22-3.14.1.s390x as component of SUSE Linux Enterprise Module for Server Applications 15", "product_id": "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x" }, "product_reference": "mariadb-client-10.2.22-3.14.1.s390x", "relates_to_product_reference": "SUSE Linux Enterprise Module for Server Applications 15" }, { "category": "default_component_of", "full_product_name": { "name": "mariadb-client-10.2.22-3.14.1.x86_64 as component of SUSE Linux Enterprise Module for Server Applications 15", "product_id": "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64" }, "product_reference": "mariadb-client-10.2.22-3.14.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Module for Server Applications 15" }, { "category": "default_component_of", "full_product_name": { "name": "mariadb-errormessages-10.2.22-3.14.1.noarch as component of SUSE Linux Enterprise Module for Server Applications 15", "product_id": "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch" }, "product_reference": "mariadb-errormessages-10.2.22-3.14.1.noarch", "relates_to_product_reference": "SUSE Linux Enterprise Module for Server Applications 15" }, { "category": "default_component_of", "full_product_name": { "name": "mariadb-tools-10.2.22-3.14.1.aarch64 as component of SUSE Linux Enterprise Module for Server Applications 15", "product_id": "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64" }, "product_reference": "mariadb-tools-10.2.22-3.14.1.aarch64", "relates_to_product_reference": "SUSE Linux Enterprise Module for Server Applications 15" }, { "category": "default_component_of", "full_product_name": { "name": "mariadb-tools-10.2.22-3.14.1.ppc64le as component of SUSE Linux Enterprise Module for Server Applications 15", "product_id": "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le" }, "product_reference": "mariadb-tools-10.2.22-3.14.1.ppc64le", "relates_to_product_reference": "SUSE Linux Enterprise Module for Server Applications 15" }, { "category": "default_component_of", "full_product_name": { "name": "mariadb-tools-10.2.22-3.14.1.s390x as component of SUSE Linux Enterprise Module for Server Applications 15", "product_id": "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x" }, "product_reference": "mariadb-tools-10.2.22-3.14.1.s390x", "relates_to_product_reference": "SUSE Linux Enterprise Module for Server Applications 15" }, { "category": "default_component_of", "full_product_name": { "name": "mariadb-tools-10.2.22-3.14.1.x86_64 as component of SUSE Linux Enterprise Module for Server Applications 15", "product_id": "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" }, "product_reference": "mariadb-tools-10.2.22-3.14.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Module for Server Applications 15" } ] }, "vulnerabilities": [ { "cve": "CVE-2016-9843", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-9843" } ], "notes": [ { "category": "general", "text": "The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-9843", "url": "https://www.suse.com/security/cve/CVE-2016-9843" }, { "category": "external", "summary": "SUSE Bug 1003580 for CVE-2016-9843", "url": "https://bugzilla.suse.com/1003580" }, { "category": "external", "summary": "SUSE Bug 1013882 for CVE-2016-9843", "url": "https://bugzilla.suse.com/1013882" }, { "category": "external", "summary": "SUSE Bug 1038505 for CVE-2016-9843", "url": "https://bugzilla.suse.com/1038505" }, { "category": "external", "summary": "SUSE Bug 1062104 for CVE-2016-9843", "url": "https://bugzilla.suse.com/1062104" }, { "category": "external", "summary": "SUSE Bug 1116686 for CVE-2016-9843", "url": "https://bugzilla.suse.com/1116686" }, { "category": "external", "summary": "SUSE Bug 1120866 for CVE-2016-9843", "url": "https://bugzilla.suse.com/1120866" }, { "category": "external", "summary": "SUSE Bug 1123150 for CVE-2016-9843", "url": "https://bugzilla.suse.com/1123150" }, { "category": "external", "summary": "SUSE Bug 1127473 for CVE-2016-9843", "url": "https://bugzilla.suse.com/1127473" }, { "category": "external", "summary": "SUSE Bug 1184301 for CVE-2016-9843", "url": "https://bugzilla.suse.com/1184301" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2019-03-06T09:55:52Z", "details": "moderate" } ], "title": "CVE-2016-9843" }, { "cve": "CVE-2018-3058", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-3058" } ], "notes": [ { "category": "general", "text": "Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: MyISAM). Supported versions that are affected are 5.5.60 and prior, 5.6.40 and prior and 5.7.22 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.0 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-3058", "url": "https://www.suse.com/security/cve/CVE-2018-3058" }, { "category": "external", "summary": "SUSE Bug 1101676 for CVE-2018-3058", "url": "https://bugzilla.suse.com/1101676" }, { "category": "external", "summary": "SUSE Bug 1116686 for CVE-2018-3058", "url": "https://bugzilla.suse.com/1116686" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N", "version": "3.0" }, "products": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2019-03-06T09:55:52Z", "details": "moderate" } ], "title": "CVE-2018-3058" }, { "cve": "CVE-2018-3060", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-3060" } ], "notes": [ { "category": "general", "text": "Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.7.22 and prior and 8.0.11 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all MySQL Server accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 6.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H).", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-3060", "url": "https://www.suse.com/security/cve/CVE-2018-3060" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2019-03-06T09:55:52Z", "details": "moderate" } ], "title": "CVE-2018-3060" }, { "cve": "CVE-2018-3063", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-3063" } ], "notes": [ { "category": "general", "text": "Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 5.5.60 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-3063", "url": "https://www.suse.com/security/cve/CVE-2018-3063" }, { "category": "external", "summary": "SUSE Bug 1101677 for CVE-2018-3063", "url": "https://bugzilla.suse.com/1101677" }, { "category": "external", "summary": "SUSE Bug 1116686 for CVE-2018-3063", "url": "https://bugzilla.suse.com/1116686" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.9, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H", "version": "3.0" }, "products": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2019-03-06T09:55:52Z", "details": "moderate" } ], "title": "CVE-2018-3063" }, { "cve": "CVE-2018-3064", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-3064" } ], "notes": [ { "category": "general", "text": "Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.6.40 and prior, 5.7.22 and prior and 8.0.11 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.0 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H).", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-3064", "url": "https://www.suse.com/security/cve/CVE-2018-3064" }, { "category": "external", "summary": "SUSE Bug 1103342 for CVE-2018-3064", "url": "https://bugzilla.suse.com/1103342" }, { "category": "external", "summary": "SUSE Bug 1116686 for CVE-2018-3064", "url": "https://bugzilla.suse.com/1116686" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.1, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H", "version": "3.0" }, "products": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2019-03-06T09:55:52Z", "details": "important" } ], "title": "CVE-2018-3064" }, { "cve": "CVE-2018-3066", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-3066" } ], "notes": [ { "category": "general", "text": "Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Options). Supported versions that are affected are 5.5.60 and prior, 5.6.40 and prior and 5.7.22 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server accessible data as well as unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.0 Base Score 3.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N).", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-3066", "url": "https://www.suse.com/security/cve/CVE-2018-3066" }, { "category": "external", "summary": "SUSE Bug 1101678 for CVE-2018-3066", "url": "https://bugzilla.suse.com/1101678" }, { "category": "external", "summary": "SUSE Bug 1116686 for CVE-2018-3066", "url": "https://bugzilla.suse.com/1116686" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 3.3, "baseSeverity": "LOW", "vectorString": "CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N", "version": "3.0" }, "products": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2019-03-06T09:55:52Z", "details": "low" } ], "title": "CVE-2018-3066" }, { "cve": "CVE-2018-3143", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-3143" } ], "notes": [ { "category": "general", "text": "Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.6.41 and prior, 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-3143", "url": "https://www.suse.com/security/cve/CVE-2018-3143" }, { "category": "external", "summary": "SUSE Bug 1112421 for CVE-2018-3143", "url": "https://bugzilla.suse.com/1112421" }, { "category": "external", "summary": "SUSE Bug 1116686 for CVE-2018-3143", "url": "https://bugzilla.suse.com/1116686" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2019-03-06T09:55:52Z", "details": "moderate" } ], "title": "CVE-2018-3143" }, { "cve": "CVE-2018-3156", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-3156" } ], "notes": [ { "category": "general", "text": "Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.6.41 and prior, 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-3156", "url": "https://www.suse.com/security/cve/CVE-2018-3156" }, { "category": "external", "summary": "SUSE Bug 1112417 for CVE-2018-3156", "url": "https://bugzilla.suse.com/1112417" }, { "category": "external", "summary": "SUSE Bug 1116686 for CVE-2018-3156", "url": "https://bugzilla.suse.com/1116686" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2019-03-06T09:55:52Z", "details": "moderate" } ], "title": "CVE-2018-3156" }, { "cve": "CVE-2018-3162", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-3162" } ], "notes": [ { "category": "general", "text": "Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-3162", "url": "https://www.suse.com/security/cve/CVE-2018-3162" }, { "category": "external", "summary": "SUSE Bug 1112415 for CVE-2018-3162", "url": "https://bugzilla.suse.com/1112415" }, { "category": "external", "summary": "SUSE Bug 1116686 for CVE-2018-3162", "url": "https://bugzilla.suse.com/1116686" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.9, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2019-03-06T09:55:52Z", "details": "moderate" } ], "title": "CVE-2018-3162" }, { "cve": "CVE-2018-3173", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-3173" } ], "notes": [ { "category": "general", "text": "Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-3173", "url": "https://www.suse.com/security/cve/CVE-2018-3173" }, { "category": "external", "summary": "SUSE Bug 1112386 for CVE-2018-3173", "url": "https://bugzilla.suse.com/1112386" }, { "category": "external", "summary": "SUSE Bug 1116686 for CVE-2018-3173", "url": "https://bugzilla.suse.com/1116686" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.9, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2019-03-06T09:55:52Z", "details": "moderate" } ], "title": "CVE-2018-3173" }, { "cve": "CVE-2018-3174", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-3174" } ], "notes": [ { "category": "general", "text": "Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.5.61 and prior, 5.6.41 and prior, 5.7.23 and prior and 8.0.12 and prior. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. While the vulnerability is in MySQL Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H).", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-3174", "url": "https://www.suse.com/security/cve/CVE-2018-3174" }, { "category": "external", "summary": "SUSE Bug 1112368 for CVE-2018-3174", "url": "https://bugzilla.suse.com/1112368" }, { "category": "external", "summary": "SUSE Bug 1116686 for CVE-2018-3174", "url": "https://bugzilla.suse.com/1116686" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H", "version": "3.0" }, "products": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2019-03-06T09:55:52Z", "details": "moderate" } ], "title": "CVE-2018-3174" }, { "cve": "CVE-2018-3185", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-3185" } ], "notes": [ { "category": "general", "text": "Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.0 Base Score 5.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-3185", "url": "https://www.suse.com/security/cve/CVE-2018-3185" }, { "category": "external", "summary": "SUSE Bug 1112384 for CVE-2018-3185", "url": "https://bugzilla.suse.com/1112384" }, { "category": "external", "summary": "SUSE Bug 1116686 for CVE-2018-3185", "url": "https://bugzilla.suse.com/1116686" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2019-03-06T09:55:52Z", "details": "moderate" } ], "title": "CVE-2018-3185" }, { "cve": "CVE-2018-3200", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-3200" } ], "notes": [ { "category": "general", "text": "Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-3200", "url": "https://www.suse.com/security/cve/CVE-2018-3200" }, { "category": "external", "summary": "SUSE Bug 1112404 for CVE-2018-3200", "url": "https://bugzilla.suse.com/1112404" }, { "category": "external", "summary": "SUSE Bug 1116686 for CVE-2018-3200", "url": "https://bugzilla.suse.com/1116686" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.9, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2019-03-06T09:55:52Z", "details": "moderate" } ], "title": "CVE-2018-3200" }, { "cve": "CVE-2018-3251", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-3251" } ], "notes": [ { "category": "general", "text": "Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.6.41 and prior, 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-3251", "url": "https://www.suse.com/security/cve/CVE-2018-3251" }, { "category": "external", "summary": "SUSE Bug 1112397 for CVE-2018-3251", "url": "https://bugzilla.suse.com/1112397" }, { "category": "external", "summary": "SUSE Bug 1116686 for CVE-2018-3251", "url": "https://bugzilla.suse.com/1116686" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.0" }, "products": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2019-03-06T09:55:52Z", "details": "moderate" } ], "title": "CVE-2018-3251" }, { "cve": "CVE-2018-3277", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-3277" } ], "notes": [ { "category": "general", "text": "Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-3277", "url": "https://www.suse.com/security/cve/CVE-2018-3277" }, { "category": "external", "summary": "SUSE Bug 1112391 for CVE-2018-3277", "url": "https://bugzilla.suse.com/1112391" }, { "category": "external", "summary": "SUSE Bug 1116686 for CVE-2018-3277", "url": "https://bugzilla.suse.com/1116686" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.9, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2019-03-06T09:55:52Z", "details": "moderate" } ], "title": "CVE-2018-3277" }, { "cve": "CVE-2018-3282", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-3282" } ], "notes": [ { "category": "general", "text": "Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Storage Engines). Supported versions that are affected are 5.5.61 and prior, 5.6.41 and prior, 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-3282", "url": "https://www.suse.com/security/cve/CVE-2018-3282" }, { "category": "external", "summary": "SUSE Bug 1112432 for CVE-2018-3282", "url": "https://bugzilla.suse.com/1112432" }, { "category": "external", "summary": "SUSE Bug 1116686 for CVE-2018-3282", "url": "https://bugzilla.suse.com/1116686" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.9, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H", "version": "3.0" }, "products": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2019-03-06T09:55:52Z", "details": "moderate" } ], "title": "CVE-2018-3282" }, { "cve": "CVE-2018-3284", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-3284" } ], "notes": [ { "category": "general", "text": "Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.7.23 and prior and 8.0.12 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-3284", "url": "https://www.suse.com/security/cve/CVE-2018-3284" }, { "category": "external", "summary": "SUSE Bug 1112377 for CVE-2018-3284", "url": "https://bugzilla.suse.com/1112377" }, { "category": "external", "summary": "SUSE Bug 1116686 for CVE-2018-3284", "url": "https://bugzilla.suse.com/1116686" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.4, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H", "version": "3.0" }, "products": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2019-03-06T09:55:52Z", "details": "moderate" } ], "title": "CVE-2018-3284" }, { "cve": "CVE-2019-2510", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2019-2510" } ], "notes": [ { "category": "general", "text": "Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2019-2510", "url": "https://www.suse.com/security/cve/CVE-2019-2510" }, { "category": "external", "summary": "SUSE Bug 1122198 for CVE-2019-2510", "url": "https://bugzilla.suse.com/1122198" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.9, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H", "version": "3.0" }, "products": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2019-03-06T09:55:52Z", "details": "important" } ], "title": "CVE-2019-2510" }, { "cve": "CVE-2019-2537", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2019-2537" } ], "notes": [ { "category": "general", "text": "Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.6.42 and prior, 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2019-2537", "url": "https://www.suse.com/security/cve/CVE-2019-2537" }, { "category": "external", "summary": "SUSE Bug 1122198 for CVE-2019-2537", "url": "https://bugzilla.suse.com/1122198" }, { "category": "external", "summary": "SUSE Bug 1136037 for CVE-2019-2537", "url": "https://bugzilla.suse.com/1136037" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.9, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H", "version": "3.0" }, "products": [ "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld-devel-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:libmysqld19-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-client-10.2.22-3.14.1.x86_64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-errormessages-10.2.22-3.14.1.noarch", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.aarch64", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.ppc64le", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.s390x", "SUSE Linux Enterprise Module for Server Applications 15:mariadb-tools-10.2.22-3.14.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2019-03-06T09:55:52Z", "details": "important" } ], "title": "CVE-2019-2537" } ] }
Loading…
Loading…
Sightings
Author | Source | Type | Date |
---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…