openSUSE 安全性更新:MariaDB (openSUSE-2015-479) (BACKRONYM) (Logjam)

high Nessus Plugin ID 84658

概要

遠端 openSUSE 主機缺少安全性更新。

說明

MariaDB 已更新至最新的次要版本,可修正錯誤和安全性問題。

這些更新中包含一個 Logjam 修正 (CVE-2015-4000),讓 MariaDB 可搭配用戶端軟體 (該軟體不再允許透過 SSL 的短 DH 群組) 使用,例如最新版 openssl 套件。

在 openSUSE 13.1 中,MariaDB 已更新至 5.5.44 版。

在 openSUSE 13.2 中,MariaDB 已從 10.0.13 更新至 10.0.20 版。

如需詳細資訊,請參閱 MariaDB 的版本資訊:https://mariadb.com/kb/en/mariadb/mariadb-10020-release-notes/ https://mariadb.com/kb/en/mariadb/mariadb-10019-release-notes/ https://mariadb.com/kb/en/mariadb/mariadb-10018-release-notes/ https://mariadb.com/kb/en/mariadb/mariadb-10017-release-notes/ https://mariadb.com/kb/en/mariadb/mariadb-10016-release-notes/ https://mariadb.com/kb/en/mariadb/mariadb-10015-release-notes/ https://mariadb.com/kb/en/mariadb/mariadb-10014-release-notes/。

解決方案

更新受影響的 MariaDB 套件。

另請參閱

https://bugzilla.opensuse.org/show_bug.cgi?id=859345

https://bugzilla.opensuse.org/show_bug.cgi?id=914370

https://bugzilla.opensuse.org/show_bug.cgi?id=924663

https://bugzilla.opensuse.org/show_bug.cgi?id=934789

https://bugzilla.opensuse.org/show_bug.cgi?id=936407

https://bugzilla.opensuse.org/show_bug.cgi?id=936408

https://bugzilla.opensuse.org/show_bug.cgi?id=936409

https://mariadb.com/kb/en/library/mariadb-10014-release-notes/

https://mariadb.com/kb/en/library/mariadb-10015-release-notes/

https://mariadb.com/kb/en/library/mariadb-10016-release-notes/

https://mariadb.com/kb/en/library/mariadb-10017-release-notes/

https://mariadb.com/kb/en/library/mariadb-10018-release-notes/

https://mariadb.com/kb/en/library/mariadb-10019-release-notes/

https://mariadb.com/kb/en/library/mariadb-10020-release-notes/

Plugin 詳細資訊

嚴重性: High

ID: 84658

檔案名稱: openSUSE-2015-479.nasl

版本: 1.14

類型: local

代理程式: unix

已發布: 2015/7/13

已更新: 2022/12/5

支援的感應器: Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Nessus

風險資訊

VPR

風險因素: Medium

分數: 6.7

CVSS v2

風險因素: High

基本分數: 7.5

媒介: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS v3

風險因素: High

基本分數: 7.8

媒介: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

弱點資訊

CPE: p-cpe:/a:novell:opensuse:libmysqlclient-devel, p-cpe:/a:novell:opensuse:libmysqlclient18, p-cpe:/a:novell:opensuse:libmysqlclient18-32bit, p-cpe:/a:novell:opensuse:libmysqlclient18-debuginfo, p-cpe:/a:novell:opensuse:libmysqlclient18-debuginfo-32bit, p-cpe:/a:novell:opensuse:libmysqlclient_r18, p-cpe:/a:novell:opensuse:libmysqlclient_r18-32bit, p-cpe:/a:novell:opensuse:libmysqld-devel, p-cpe:/a:novell:opensuse:libmysqld18, p-cpe:/a:novell:opensuse:libmysqld18-debuginfo, p-cpe:/a:novell:opensuse:mariadb, p-cpe:/a:novell:opensuse:mariadb-bench, p-cpe:/a:novell:opensuse:mariadb-bench-debuginfo, p-cpe:/a:novell:opensuse:mariadb-client, p-cpe:/a:novell:opensuse:mariadb-client-debuginfo, p-cpe:/a:novell:opensuse:mariadb-debuginfo, p-cpe:/a:novell:opensuse:mariadb-debugsource, p-cpe:/a:novell:opensuse:mariadb-errormessages, p-cpe:/a:novell:opensuse:mariadb-test, p-cpe:/a:novell:opensuse:mariadb-test-debuginfo, p-cpe:/a:novell:opensuse:mariadb-tools, p-cpe:/a:novell:opensuse:mariadb-tools-debuginfo, cpe:/o:novell:opensuse:13.1, cpe:/o:novell:opensuse:13.2

必要的 KB 項目: Host/local_checks_enabled, Host/SuSE/release, Host/SuSE/rpm-list, Host/cpu

修補程式發佈日期: 2015/7/1

弱點發布日期: 2014/10/15

參考資訊

CVE: CVE-2014-6464, CVE-2014-6469, CVE-2014-6491, CVE-2014-6494, CVE-2014-6496, CVE-2014-6500, CVE-2014-6507, CVE-2014-6555, CVE-2014-6559, CVE-2014-6568, CVE-2014-8964, CVE-2015-0374, CVE-2015-0381, CVE-2015-0382, CVE-2015-0411, CVE-2015-0432, CVE-2015-0433, CVE-2015-0441, CVE-2015-0499, CVE-2015-0501, CVE-2015-0505, CVE-2015-2325, CVE-2015-2326, CVE-2015-2568, CVE-2015-2571, CVE-2015-2573, CVE-2015-3152, CVE-2015-4000