Oval Definition:oval:com.redhat.rhsa:def:20151665
Revision Date:2015-08-24Version:637
Title:RHSA-2015:1665: mariadb security update (Moderate)
Description:MariaDB is a multi-user, multi-threaded SQL database server that is binary compatible with MySQL.

  • It was found that the MySQL client library permitted but did not require a client to use SSL/TLS when establishing a secure connection to a MySQL server using the "--ssl" option. A man-in-the-middle attacker could use this flaw to strip the SSL/TLS protection from a connection between a client and a server. (CVE-2015-3152)

  • This update fixes several vulnerabilities in the MariaDB database server. Information about these flaws can be found on the Oracle Critical Patch Update Advisory page, listed in the References section. (CVE-2015-0501, CVE-2015-2568, CVE-2015-0499, CVE-2015-2571, CVE-2015-0433, CVE-2015-0441, CVE-2015-0505, CVE-2015-2573, CVE-2015-2582, CVE-2015-2620, CVE-2015-2643, CVE-2015-2648, CVE-2015-4737, CVE-2015-4752, CVE-2015-4757)

    These updated packages upgrade MariaDB to version 5.5.44. Refer to the MariaDB Release Notes listed in the References section for a complete list of changes.

    All MariaDB users should upgrade to these updated packages, which correct these issues. After installing this update, the MariaDB server daemon (mysqld) will be restarted automatically.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2015-0433
    CVE-2015-0441
    CVE-2015-0499
    CVE-2015-0501
    CVE-2015-0505
    CVE-2015-2568
    CVE-2015-2571
    CVE-2015-2573
    CVE-2015-2582
    CVE-2015-2620
    CVE-2015-2643
    CVE-2015-2648
    CVE-2015-3152
    CVE-2015-4737
    CVE-2015-4752
    CVE-2015-4757
    CVE-2015-4864
    RHSA-2015:1665
    RHSA-2015:1665-00
    RHSA-2015:1665-01
    RHSA-2015:1665-03
    Platform(s):Red Hat Enterprise Linux 7
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND
  • mariadb is earlier than 1:5.5.44-1.el7_1
  • AND mariadb is signed with Red Hat redhatrelease2 key
  • mariadb-bench is earlier than 1:5.5.44-1.el7_1
  • AND mariadb-bench is signed with Red Hat redhatrelease2 key
  • mariadb-devel is earlier than 1:5.5.44-1.el7_1
  • AND mariadb-devel is signed with Red Hat redhatrelease2 key
  • mariadb-embedded is earlier than 1:5.5.44-1.el7_1
  • AND mariadb-embedded is signed with Red Hat redhatrelease2 key
  • mariadb-embedded-devel is earlier than 1:5.5.44-1.el7_1
  • AND mariadb-embedded-devel is signed with Red Hat redhatrelease2 key
  • mariadb-libs is earlier than 1:5.5.44-1.el7_1
  • AND mariadb-libs is signed with Red Hat redhatrelease2 key
  • mariadb-server is earlier than 1:5.5.44-1.el7_1
  • AND mariadb-server is signed with Red Hat redhatrelease2 key
  • mariadb-test is earlier than 1:5.5.44-1.el7_1
  • AND mariadb-test is signed with Red Hat redhatrelease2 key
  • BACK