Moderate: mariadb:10.3 security and bug fix update
MariaDB is a multi-user, multi-threaded SQL database server that is binary compatible with MySQL. The following packages have been upgraded to a later upstream version: mariadb (10.3.17), galera (25.3.26). (BZ#1701687, BZ#1711265, BZ#1741358) Security Fix(es): * mysql: InnoDB unspecified vulnerability (CPU Jan 2019) (CVE-2019-2510) * mysql: Server: DDL unspecified vulnerability (CPU Jan 2019) (CVE-2019-2537) * mysql: Server: Replication unspecified vulnerability (CPU Apr 2019) (CVE-2019-2614) * mysql: Server: Security: Privileges unspecified vulnerability (CPU Apr 2019) (CVE-2019-2627) * mysql: InnoDB unspecified vulnerability (CPU Apr 2019) (CVE-2019-2628) * mysql: Server: Pluggable Auth unspecified vulnerability (CPU Jul 2019) (CVE-2019-2737) * mysql: Server: Security: Privileges unspecified vulnerability (CPU Jul 2019) (CVE-2019-2739) * mysql: Server: XML unspecified vulnerability (CPU Jul 2019) (CVE-2019-2740) * mysql: InnoDB unspecified vulnerability (CPU Jul 2019) (CVE-2019-2758) * mysql: Server: Parser unspecified vulnerability (CPU Jul 2019) (CVE-2019-2805) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
MariaDB is a multi-user, multi-threaded SQL database server that is binary compatible with MySQL. The following packages have been upgraded to a later upstream version: mariadb (10.3.17), galera (25.3.26). (BZ#1701687, BZ#1711265, BZ#1741358) Security Fix(es): * mysql: InnoDB unspecified vulnerability (CPU Jan 2019) (CVE-2019-2510) * mysql: Server: DDL unspecified vulnerability (CPU Jan 2019) (CVE-2019-2537) * mysql: Server: Replication unspecified vulnerability (CPU Apr 2019) (CVE-2019-2614) * mysql: Server: Security: Privileges unspecified vulnerability (CPU Apr 2019) (CVE-2019-2627) * mysql: InnoDB unspecified vulnerability (CPU Apr 2019) (CVE-2019-2628) * mysql: Server: Pluggable Auth unspecified vulnerability (CPU Jul 2019) (CVE-2019-2737) * mysql: Server: Security: Privileges unspecified vulnerability (CPU Jul 2019) (CVE-2019-2739) * mysql: Server: XML unspecified vulnerability (CPU Jul 2019) (CVE-2019-2740) * mysql: InnoDB unspecified vulnerability (CPU Jul 2019) (CVE-2019-2758) * mysql: Server: Parser unspecified vulnerability (CPU Jul 2019) (CVE-2019-2805) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.
05 / REFERENCES
Further evidence
- https://access.redhat.com/errata/RHSA-2019:3708
- https://access.redhat.com/security/cve/CVE-2019-2510
- https://access.redhat.com/security/cve/CVE-2019-2537
- https://access.redhat.com/security/cve/CVE-2019-2614
- https://access.redhat.com/security/cve/CVE-2019-2627
- https://access.redhat.com/security/cve/CVE-2019-2628
- https://access.redhat.com/security/cve/CVE-2019-2737
- https://access.redhat.com/security/cve/CVE-2019-2739
- https://access.redhat.com/security/cve/CVE-2019-2740
- https://access.redhat.com/security/cve/CVE-2019-2758
- https://access.redhat.com/security/cve/CVE-2019-2805
- https://access.redhat.com/security/cve/CVE-2020-2922
- https://access.redhat.com/security/cve/CVE-2021-2007
- https://bugzilla.redhat.com/1666751
- https://bugzilla.redhat.com/1666763
- https://bugzilla.redhat.com/1702969
- https://bugzilla.redhat.com/1702976
- https://bugzilla.redhat.com/1702977
- https://bugzilla.redhat.com/1731997
- https://bugzilla.redhat.com/1731999
- https://bugzilla.redhat.com/1732000
- https://bugzilla.redhat.com/1732008
- https://bugzilla.redhat.com/1732025
- https://bugzilla.redhat.com/1835850
- https://bugzilla.redhat.com/1922382
- https://errata.almalinux.org/8/ALSA-2019-3708.html
- https://vulners.com/cve/CVE-2019-2510
- https://vulners.com/cve/CVE-2019-2537
- https://vulners.com/cve/CVE-2019-2614
- https://vulners.com/cve/CVE-2019-2627
- https://vulners.com/cve/CVE-2019-2628
- https://vulners.com/cve/CVE-2019-2737
- https://vulners.com/cve/CVE-2019-2739
- https://vulners.com/cve/CVE-2019-2740
- https://vulners.com/cve/CVE-2019-2758
- https://vulners.com/cve/CVE-2019-2805
- https://vulners.com/cve/CVE-2020-2922
- https://vulners.com/cve/CVE-2021-2007