First published: Mon Aug 12 2019(Updated: )
USN-4070-1 fixed multiple vulnerabilities in MySQL. This update provides the corresponding fixes for CVE-2019-2737, CVE-2019-2739, CVE-2019-2740, CVE-2019-2805 in MariaDB 10.1. Ubuntu 18.04 LTS has been updated to MariaDB 10.1.41. In addition to security fixes, the updated package contain bug fixes, new features, and possibly incompatible changes. Please see the following for more information: https://mariadb.com/kb/en/library/mariadb-10141-changelog/ https://mariadb.com/kb/en/library/mariadb-10141-release-notes/ Original advisory details: Multiple security issues were discovered in MySQL and this update includes a new upstream MySQL version to fix these issues. Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 19.04 have been updated to MySQL 5.7.27. In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Please see the following for more information: http://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-27.html https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libmariadbclient-dev | <1:10.1.41-0ubuntu0.18.04.1 | 1:10.1.41-0ubuntu0.18.04.1 |
Ubuntu OpenSSH Client | =18.04 | |
All of | ||
ubuntu/libmariadbclient-dev-compat | <1:10.1.41-0ubuntu0.18.04.1 | 1:10.1.41-0ubuntu0.18.04.1 |
Ubuntu OpenSSH Client | =18.04 | |
All of | ||
ubuntu/libmariadbclient18 | <1:10.1.41-0ubuntu0.18.04.1 | 1:10.1.41-0ubuntu0.18.04.1 |
Ubuntu OpenSSH Client | =18.04 | |
All of | ||
ubuntu/libmariadbd-dev | <1:10.1.41-0ubuntu0.18.04.1 | 1:10.1.41-0ubuntu0.18.04.1 |
Ubuntu OpenSSH Client | =18.04 | |
All of | ||
ubuntu/libmariadbd18 | <1:10.1.41-0ubuntu0.18.04.1 | 1:10.1.41-0ubuntu0.18.04.1 |
Ubuntu OpenSSH Client | =18.04 | |
All of | ||
ubuntu/mariadb-client | <1:10.1.41-0ubuntu0.18.04.1 | 1:10.1.41-0ubuntu0.18.04.1 |
Ubuntu OpenSSH Client | =18.04 | |
All of | ||
ubuntu/mariadb-client-10.1 | <1:10.1.41-0ubuntu0.18.04.1 | 1:10.1.41-0ubuntu0.18.04.1 |
Ubuntu OpenSSH Client | =18.04 | |
All of | ||
ubuntu/mariadb-client-core-10.1 | <1:10.1.41-0ubuntu0.18.04.1 | 1:10.1.41-0ubuntu0.18.04.1 |
Ubuntu OpenSSH Client | =18.04 | |
All of | ||
ubuntu/mariadb-common | <1:10.1.41-0ubuntu0.18.04.1 | 1:10.1.41-0ubuntu0.18.04.1 |
Ubuntu OpenSSH Client | =18.04 | |
All of | ||
ubuntu/mariadb-plugin-connect | <1:10.1.41-0ubuntu0.18.04.1 | 1:10.1.41-0ubuntu0.18.04.1 |
Ubuntu OpenSSH Client | =18.04 | |
All of | ||
ubuntu/mariadb-plugin-cracklib-password-check | <1:10.1.41-0ubuntu0.18.04.1 | 1:10.1.41-0ubuntu0.18.04.1 |
Ubuntu OpenSSH Client | =18.04 | |
All of | ||
ubuntu/mariadb-plugin-gssapi-client | <1:10.1.41-0ubuntu0.18.04.1 | 1:10.1.41-0ubuntu0.18.04.1 |
Ubuntu OpenSSH Client | =18.04 | |
All of | ||
ubuntu/mariadb-plugin-gssapi-server | <1:10.1.41-0ubuntu0.18.04.1 | 1:10.1.41-0ubuntu0.18.04.1 |
Ubuntu OpenSSH Client | =18.04 | |
All of | ||
ubuntu/mariadb-plugin-mroonga | <1:10.1.41-0ubuntu0.18.04.1 | 1:10.1.41-0ubuntu0.18.04.1 |
Ubuntu OpenSSH Client | =18.04 | |
All of | ||
ubuntu/mariadb-plugin-oqgraph | <1:10.1.41-0ubuntu0.18.04.1 | 1:10.1.41-0ubuntu0.18.04.1 |
Ubuntu OpenSSH Client | =18.04 | |
All of | ||
ubuntu/mariadb-plugin-spider | <1:10.1.41-0ubuntu0.18.04.1 | 1:10.1.41-0ubuntu0.18.04.1 |
Ubuntu OpenSSH Client | =18.04 | |
All of | ||
ubuntu/mariadb-plugin-tokudb | <1:10.1.41-0ubuntu0.18.04.1 | 1:10.1.41-0ubuntu0.18.04.1 |
Ubuntu OpenSSH Client | =18.04 | |
All of | ||
ubuntu/mariadb-server | <1:10.1.41-0ubuntu0.18.04.1 | 1:10.1.41-0ubuntu0.18.04.1 |
Ubuntu OpenSSH Client | =18.04 | |
All of | ||
ubuntu/mariadb-server-10.1 | <1:10.1.41-0ubuntu0.18.04.1 | 1:10.1.41-0ubuntu0.18.04.1 |
Ubuntu OpenSSH Client | =18.04 | |
All of | ||
ubuntu/mariadb-server-core-10.1 | <1:10.1.41-0ubuntu0.18.04.1 | 1:10.1.41-0ubuntu0.18.04.1 |
Ubuntu OpenSSH Client | =18.04 | |
All of | ||
ubuntu/mariadb-test | <1:10.1.41-0ubuntu0.18.04.1 | 1:10.1.41-0ubuntu0.18.04.1 |
Ubuntu OpenSSH Client | =18.04 | |
All of | ||
ubuntu/mariadb-test-data | <1:10.1.41-0ubuntu0.18.04.1 | 1:10.1.41-0ubuntu0.18.04.1 |
Ubuntu OpenSSH Client | =18.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
USN-4070-2 addresses vulnerabilities identified by CVE-2019-2737, CVE-2019-2739, CVE-2019-2740, and CVE-2019-2805 in MariaDB 10.1.
The vulnerabilities fixed in USN-4070-2 are assessed with various severity levels, typically ranging from low to medium risk.
To resolve USN-4070-2, update your MariaDB installation to version 10.1.41 or higher on Ubuntu 18.04.
USN-4070-2 affects Ubuntu version 18.04 LTS.
The packages that should be updated include libmariadbclient-dev, mariadb-server, and several others listed in the advisory.