A community-mysql security update is available for Fedora 30
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2019-48a0a07033
2019-11-12 02:08:10.642443
--------------------------------------------------------------------------------
Name : community-mysql
Product : Fedora 30
Version : 8.0.18
Release : 1.fc30
URL : http://www.mysql.com
Summary : MySQL client programs and shared libraries
Description :
MySQL is a multi-user, multi-threaded SQL database server. MySQL is a
client/server implementation consisting of a server daemon (mysqld)
and many different client programs and libraries. The base package
contains the standard MySQL client programs and generic MySQL files.
--------------------------------------------------------------------------------
Update Information:
**MySQL 8.0.18** Release notes:
https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-18.html CVEs fixed:
CVE-2019-2911 CVE-2019-2914 CVE-2019-2938 CVE-2019-2946 CVE-2019-2957
CVE-2019-2960 CVE-2019-2963 CVE-2019-2966 CVE-2019-2967 CVE-2019-2968
CVE-2019-2974 CVE-2019-2982 CVE-2019-2991 CVE-2019-2993 CVE-2019-2997
CVE-2019-2998 CVE-2019-3004 CVE-2019-3009 CVE-2019-3011 CVE-2019-3018
https://bugzilla.redhat.com/show_bug.cgi?id=1768175
https://www.oracle.com/security-alerts/cpuoct2019.html Maintainer notes:
linking with GOLD disabled on armv7hl, because of
https://bugs.mysql.com/bug.php?id=96698
--------------------------------------------------------------------------------
ChangeLog:
* Mon Oct 14 2019 Lars Tangvald - 8.0.18-1
- Update to MySQL 8.0.18
* Mon Aug 19 2019 Michal Schorm - 8.0.17-2
- Use RELRO hardening on all binaries
* Wed Jul 31 2019 Lars Tangvald - 8.0.17-1
- Update to MySQL 8.0.17
* Wed Jul 24 2019 Fedora Release Engineering - 8.0.16-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild
* Wed May 1 2019 Michal Schorm - 8.0.16-2
- Remove SysVInit stuff, no longer needed
- Clean up the SPECfile
* Fri Apr 26 2019 Lars Tangvald - 8.0.16-1
- Update to MySQL 8.0.16
- Rediff sharedir patch
- Refresh skip list and use new, required format
- Remove GCC9 patch now upstream
- Upstream: my_safe_process renamed and moved into proper location
- Use upstream option to skip router build
- OpenSSL 1.1.1 and TLSv1.3 is now supported, enable tests
- Update version of bundled Boost
- Start requiring mysql-selinux package
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1761354 - community-mysql-8.0.18 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1761354
[ 2 ] Bug #1768175 - CVE-2019-2911 CVE-2019-2914 CVE-2019-2938 CVE-2019-2946 CVE-2019-2957 CVE-2019-2960 CVE-2019-2963 CVE-2019-2966 CVE-2019-2967 CVE-2019-2968 CVE-2019-2974 CVE-2019-2982 CVE-2019-2991 CVE-2019-2993 ... community-mysql: various flaws [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1768175
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2019-48a0a07033' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys