[Bug 1122204] VUL-0: CVE-2019-2435: python-mysql-connector-python: Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/Python).
http://bugzilla.suse.com/show_bug.cgi?id=1122204 http://bugzilla.suse.com/show_bug.cgi?id=1122204#c5 --- Comment #5 from Dirk Mueller <dmueller@suse.com> --- So this is actually only used by python-peewee newer than 3.12, which only exists in Tumbleweed. For Tumbleweed I switched now to PyMySQL as the peewee driver so this is no longer actually used. Now I submitted a version update to 8.0.19 which I think fixes this issue (amongst everything else including a completely new api). I am not able to identify a smaller patch nor do I think we should keep patching version 2.1.x of the driver when version 8.x is around. Nothing depends on this as far as I can say, so I'd also be fine with dropping it. -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@novell.com