{"affected":[{"ecosystem_specific":{"binaries":[{"libmysql55client_r18-32bit":"5.5.55-0.38.1","libmysql55client_r18-x86":"5.5.55-0.38.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Software Development Kit 11 SP4","name":"mysql","purl":"pkg:rpm/suse/mysql&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"5.5.55-0.38.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libmysql55client18":"5.5.55-0.38.1","libmysql55client18-32bit":"5.5.55-0.38.1","libmysql55client18-x86":"5.5.55-0.38.1","libmysql55client_r18":"5.5.55-0.38.1","libmysql55client_r18-32bit":"5.5.55-0.38.1","libmysql55client_r18-x86":"5.5.55-0.38.1","mysql":"5.5.55-0.38.1","mysql-client":"5.5.55-0.38.1","mysql-tools":"5.5.55-0.38.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 11 SP4","name":"mysql","purl":"pkg:rpm/suse/mysql&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"5.5.55-0.38.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libmysql55client18":"5.5.55-0.38.1","libmysql55client18-32bit":"5.5.55-0.38.1","libmysql55client18-x86":"5.5.55-0.38.1","libmysql55client_r18":"5.5.55-0.38.1","libmysql55client_r18-32bit":"5.5.55-0.38.1","libmysql55client_r18-x86":"5.5.55-0.38.1","mysql":"5.5.55-0.38.1","mysql-client":"5.5.55-0.38.1","mysql-tools":"5.5.55-0.38.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 11 SP4","name":"mysql","purl":"pkg:rpm/suse/mysql&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"5.5.55-0.38.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"\nThis update for mysql to version 5.5.55 fixes the following issues:\n\nThese security issues were fixed:\n\n- CVE-2017-3308: Unspecified vulnerability in Server: DML (bsc#1034850)\n- CVE-2017-3309: Unspecified vulnerability in Server: Optimizer (bsc#1034850)\n- CVE-2017-3329: Unspecified vulnerability in Server: Thread (bsc#1034850)\n- CVE-2017-3600: Unspecified vulnerability in Client: mysqldump (bsc#1034850)\n- CVE-2017-3453: Unspecified vulnerability in Server: Optimizer (bsc#1034850)\n- CVE-2017-3456: Unspecified vulnerability in Server: DML (bsc#1034850)\n- CVE-2017-3463: Unspecified vulnerability in Server: Security (bsc#1034850)\n- CVE-2017-3462: Unspecified vulnerability in Server: Security (bsc#1034850)\n- CVE-2017-3461: Unspecified vulnerability in Server: Security (bsc#1034850)\n- CVE-2017-3464: Unspecified vulnerability in Server: DDL (bsc#1034850)\n- CVE-2017-3305: MySQL client sent authentication request unencrypted even if SSL was required (aka Ridddle) (bsc#1029396).\n- CVE-2016-5483: Mysqldump failed to properly quote certain identifiers in SQL statements written to the dump output, allowing for execution of arbitrary commands (bsc#1029014)\n- '--ssl-mode=REQUIRED' can be specified to require a secure connection (it fails if a secure connection cannot be obtained)\n\nThis non-security issue was fixed:\n\n- Set the default umask to 077 in rc.mysql-multi [bsc#1020976]\n\nFor additional changes please see\nhttp://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-55.html\n\nNote: The issue tracked in bsc#1022428 and fixed in the last update was\nassigned CVE-2017-3302.\n","id":"SUSE-SU-2017:1137-1","modified":"2017-04-28T15:34:16Z","published":"2017-04-28T15:34:16Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2017/suse-su-20171137-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1020976"},{"type":"REPORT","url":"https://bugzilla.suse.com/1022428"},{"type":"REPORT","url":"https://bugzilla.suse.com/1029014"},{"type":"REPORT","url":"https://bugzilla.suse.com/1029396"},{"type":"REPORT","url":"https://bugzilla.suse.com/1034850"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-5483"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-3302"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-3305"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-3308"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-3309"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-3329"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-3453"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-3456"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-3461"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-3462"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-3463"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-3464"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-3600"}],"related":["CVE-2016-5483","CVE-2017-3302","CVE-2017-3305","CVE-2017-3308","CVE-2017-3309","CVE-2017-3329","CVE-2017-3453","CVE-2017-3456","CVE-2017-3461","CVE-2017-3462","CVE-2017-3463","CVE-2017-3464","CVE-2017-3600"],"summary":"Security update for mysql","upstream":["CVE-2016-5483","CVE-2017-3302","CVE-2017-3305","CVE-2017-3308","CVE-2017-3309","CVE-2017-3329","CVE-2017-3453","CVE-2017-3456","CVE-2017-3461","CVE-2017-3462","CVE-2017-3463","CVE-2017-3464","CVE-2017-3600"]}