[SECURITY] Fedora 15 Update: mysql-5.5.20-1.fc15

updates at fedoraproject.org updates at fedoraproject.org
Sun Feb 12 22:51:41 UTC 2012


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2012-0987
2012-01-28 02:43:41
--------------------------------------------------------------------------------

Name        : mysql
Product     : Fedora 15
Version     : 5.5.20
Release     : 1.fc15
URL         : http://www.mysql.com
Summary     : MySQL client programs and shared libraries
Description :
MySQL is a multi-user, multi-threaded SQL database server. MySQL is a
client/server implementation consisting of a server daemon (mysqld)
and many different client programs and libraries. The base package
contains the standard MySQL client programs and generic MySQL files.

--------------------------------------------------------------------------------
Update Information:

Update to MySQL 5.5.20, for various fixes described at http://dev.mysql.com/doc/refman/5.5/en/news-5-5-20.html as well as security fixes described at http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html
--------------------------------------------------------------------------------
ChangeLog:

* Fri Jan 27 2012 Tom Lane <tgl at redhat.com> 5.5.20-1
- Update to MySQL 5.5.20, for various fixes described at
  http://dev.mysql.com/doc/refman/5.5/en/news-5-5-20.html
  as well as security fixes described at
  http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html
Resolves: #783828
* Wed Jan  4 2012 Tom Lane <tgl at redhat.com> 5.5.19-1
- Update to MySQL 5.5.19, for various fixes described at
  http://dev.mysql.com/doc/refman/5.5/en/news-5-5-19.html
* Mon Nov 21 2011 Tom Lane <tgl at redhat.com> 5.5.18-1
- Update to MySQL 5.5.18, for various fixes described at
  http://dev.mysql.com/doc/refman/5.5/en/news-5-5-18.html
- Don't assume all ethernet devices are named ethX
Resolves: #682365
* Sun Oct 16 2011 Tom Lane <tgl at redhat.com> 5.5.15-1.1
- Fix unportable usage associated with va_list arguments
Resolves: #744707
* Fri Jul 29 2011 Tom Lane <tgl at redhat.com> 5.5.15-1
- Update to MySQL 5.5.15, for various fixes described at
  http://dev.mysql.com/doc/refman/5.5/en/news-5-5-15.html
* Tue Jul 12 2011 Tom Lane <tgl at redhat.com> 5.5.14-2
- Remove make_scrambled_password and make_scrambled_password_323 from mysql.h,
  since we're not allowing clients to call those functions anyway
Related: #690346
* Mon Jul 11 2011 Tom Lane <tgl at redhat.com> 5.5.14-1
- Update to MySQL 5.5.14, for various fixes described at
  http://dev.mysql.com/doc/refman/5.5/en/news-5-5-14.html
* Wed Jul  6 2011 Tom Lane <tgl at redhat.com> 5.5.13-2
- Remove erroneously-included Default-Start line from LSB init block
Resolves: #717024
* Thu Jun  2 2011 Tom Lane <tgl at redhat.com> 5.5.13-1
- Update to MySQL 5.5.13, for various fixes described at
  http://dev.mysql.com/doc/refman/5.5/en/news-5-5-13.html
* Tue May 10 2011 Tom Lane <tgl at redhat.com> 5.5.12-1
- Update to MySQL 5.5.12, for various fixes described at
  http://dev.mysql.com/doc/refman/5.5/en/news-5-5-12.html
* Tue May 10 2011 Tom Lane <tgl at redhat.com> 5.5.10-3
- Add LSB init block to initscript, to ensure sane ordering at system boot
Resolves: #703214
- Improve initscript start action to notice when mysqladmin is failing
  because of configuration problems
Related: #703476
- Remove exclusion of "gis" regression test, since upstream bug 59908
  is fixed (for some value of "fixed") as of 5.5.10.
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #783793 - CVE-2011-2262 mysql: Unspecified vulnerability allows remote attackers to affect availability
        https://bugzilla.redhat.com/show_bug.cgi?id=783793
  [ 2 ] Bug #783794 - CVE-2012-0075 mysql: Unspecified vulnerability allows remote authenticated users to affect integrity
        https://bugzilla.redhat.com/show_bug.cgi?id=783794
  [ 3 ] Bug #783799 - CVE-2012-0112 mysql: Unspecified vulnerability allows remote authenticated users to affect availability
        https://bugzilla.redhat.com/show_bug.cgi?id=783799
  [ 4 ] Bug #783800 - CVE-2012-0113 mysql: Unspecified vulnerability allows remote authenticated users to affect confidentiality and availability
        https://bugzilla.redhat.com/show_bug.cgi?id=783800
  [ 5 ] Bug #783801 - CVE-2012-0114 mysql: Unspecified vulnerability allows local users to affect confidentiality and integrity
        https://bugzilla.redhat.com/show_bug.cgi?id=783801
  [ 6 ] Bug #783802 - CVE-2012-0115 mysql: Unspecified vulnerability allows remote authenticated users to affect availability
        https://bugzilla.redhat.com/show_bug.cgi?id=783802
  [ 7 ] Bug #783803 - CVE-2012-0116 mysql: Unspecified vulnerability allows remote authenticated users to affect confidentiality and integrity
        https://bugzilla.redhat.com/show_bug.cgi?id=783803
  [ 8 ] Bug #783804 - CVE-2012-0117 mysql: Unspecified vulnerability allows remote authenticated users to affect availability via unknown vectors
        https://bugzilla.redhat.com/show_bug.cgi?id=783804
  [ 9 ] Bug #783805 - CVE-2012-0118 mysql: Unspecified vulnerability allows remote authenticated users to affect confidentiality and availability
        https://bugzilla.redhat.com/show_bug.cgi?id=783805
  [ 10 ] Bug #783806 - CVE-2012-0119 mysql: Unspecified vulnerability allows remote authenticated users to affect availability
        https://bugzilla.redhat.com/show_bug.cgi?id=783806
  [ 11 ] Bug #783807 - CVE-2012-0120 mysql: Unspecified vulnerability allows remote authenticated users to affect availability
        https://bugzilla.redhat.com/show_bug.cgi?id=783807
  [ 12 ] Bug #783808 - CVE-2012-0484 mysql: Unspecified vulnerability allows remote authenticated users to affect confidentiality
        https://bugzilla.redhat.com/show_bug.cgi?id=783808
  [ 13 ] Bug #783809 - CVE-2012-0485 mysql: Unspecified vulnerability allows remote authenticated users to affect availability
        https://bugzilla.redhat.com/show_bug.cgi?id=783809
  [ 14 ] Bug #783810 - CVE-2012-0486 mysql: Unspecified vulnerability allows remote authenticated users to affect availability via unknown vectors
        https://bugzilla.redhat.com/show_bug.cgi?id=783810
  [ 15 ] Bug #783812 - CVE-2012-0487 mysql: Unspecified vulnerability allows remote authenticated users to affect availability via unknown vectors
        https://bugzilla.redhat.com/show_bug.cgi?id=783812
  [ 16 ] Bug #783813 - CVE-2012-0488 mysql: Unspecified vulnerability allows remote authenticated users to affect availability via unknown vectors
        https://bugzilla.redhat.com/show_bug.cgi?id=783813
  [ 17 ] Bug #783814 - CVE-2012-0489 mysql: Unspecified vulnerability allows remote authenticated users to affect availability via unknown vectors
        https://bugzilla.redhat.com/show_bug.cgi?id=783814
  [ 18 ] Bug #783815 - CVE-2012-0490 mysql: Unspecified vulnerability allows remote authenticated users to affect availability
        https://bugzilla.redhat.com/show_bug.cgi?id=783815
  [ 19 ] Bug #783816 - CVE-2012-0491 mysql: Unspecified vulnerability allows remote authenticated users to affect availability via unknown vectors
        https://bugzilla.redhat.com/show_bug.cgi?id=783816
  [ 20 ] Bug #783817 - CVE-2012-0492 mysql: Unspecified vulnerability allows remote authenticated users to affect availability
        https://bugzilla.redhat.com/show_bug.cgi?id=783817
  [ 21 ] Bug #783818 - CVE-2012-0493 mysql: Unspecified vulnerability allows remote authenticated users to affect availability via unknown vectors
        https://bugzilla.redhat.com/show_bug.cgi?id=783818
  [ 22 ] Bug #783819 - CVE-2012-0494 mysql: Unspecified vulnerability allows local users to affect availability via unknown vectors
        https://bugzilla.redhat.com/show_bug.cgi?id=783819
  [ 23 ] Bug #783820 - CVE-2012-0495 mysql: Unspecified vulnerability allows remote authenticated users to affect availability via unknown vectors
        https://bugzilla.redhat.com/show_bug.cgi?id=783820
  [ 24 ] Bug #783821 - CVE-2012-0496 mysql: Unspecified vulnerability allows remote authenticated users to affect confidentiality and integrity via unknown vectors
        https://bugzilla.redhat.com/show_bug.cgi?id=783821
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use 
su -c 'yum update mysql' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


More information about the package-announce mailing list