openSUSE-SU-2015:0967-1: moderate: Security update for mysql-connector-java
openSUSE Security Update: Security update for mysql-connector-java ______________________________________________________________________________ Announcement ID: openSUSE-SU-2015:0967-1 Rating: moderate References: #927981 Cross-References: CVE-2015-2575 Affected Products: openSUSE 13.2 openSUSE 13.1 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: mysql-connector-java was updated to 5.1.35 to fix one security issue and a number of bugs. The following vulnerability was fixed: * CVE-2015-2575: Difficult to exploit vulnerability allows successful authenticated network attacks via multiple protocols. Successful attack of this vulnerability can result in unauthorized update, insert or delete access to some MySQL Connectors accessible data as well as read access to a subset of MySQL Connectors accessible data. In addition, mysql-connector-java was updated to 5.1.35 to fix a number of upstream bugs, details of which listed in CHANGES as well as http://dev.mysql.com/doc/relnotes/connector-j/en/news-5-1.html Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE 13.2: zypper in -t patch openSUSE-2015-389=1 - openSUSE 13.1: zypper in -t patch openSUSE-2015-389=1 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE 13.2 (noarch): mysql-connector-java-5.1.35-3.3.1 - openSUSE 13.1 (noarch): mysql-connector-java-5.1.35-3.1 References: https://www.suse.com/security/cve/CVE-2015-2575.html https://bugzilla.suse.com/927981
participants (1)
-
opensuse-security@opensuse.org