openSUSE Security Update: Security update for xtrabackup ______________________________________________________________________________ Announcement ID: openSUSE-SU-2017:0830-1 Rating: moderate References: #1026729 Affected Products: openSUSE Leap 42.2 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update to xtrabackup 2.3.7 fixes one security issue and bugs. The following security issue was fixed: - innobackupex and xtrabackup scripts were showing the password in the ps output when it was passed as a command line argument (boo#1026729) The following functionality was added: - new --remove-original option for removing the original encrypted and compressed files - now supports -H, -h, -u and -p shortcuts for --hostname, --datadir, --user and --password respectively The following bugs were fixed: - Pick up username from user's configuration file correctly - Incremental backups did not include xtrabackup_binlog_info and xtrabackup_galera_info files - --move-back option did not always restore out-of-datadir tablespaces to their original directories - Incremental backup would fail with a path like ~/backup/inc_1 Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE Leap 42.2: zypper in -t patch openSUSE-2017-382=1 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE Leap 42.2 (x86_64): xtrabackup-2.3.7-5.3.1 xtrabackup-debuginfo-2.3.7-5.3.1 xtrabackup-debugsource-2.3.7-5.3.1 xtrabackup-test-2.3.7-5.3.1 References: https://bugzilla.suse.com/1026729