SB2016111205 - SUSE Linux update for mysql
Published: November 12, 2016
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 secuirty vulnerabilities.
1) Information disclosure (CVE-ID: CVE-2016-5584)
The vulnerability allows a remote privileged user to gain access to sensitive information.
Unspecified vulnerability in Oracle MySQL 5.5.52 and earlier, 5.6.33 and earlier, and 5.7.15 and earlier allows remote administrators to affect confidentiality via vectors related to Server: Security: Encryption.
2) Arbitrary command execution (CVE-ID: CVE-2016-6662)
The vulnerability allows an administrative user to execute arbitrary command on the target system.The weakness exists due to insufficient access control that allows a malicious user to execute arbitrary command with root privileges that may lead to complete system compromise.
Successful exploitation of the vulnerability results in arbitrary code excution on the vulnerable system.
3) Cryptographic issues (CVE-ID: CVE-2016-7440)
The vulnerability allows a local authenticated user to gain access to sensitive information.
The C software implementation of AES Encryption and Decryption in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover AES keys by leveraging cache-bank timing differences.
Remediation
Install update from vendor's website.