Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 597556 (CVE-2016-5598) - <dev-python/mysql-connector-python-2.1.4: Remote security vulnerability (CPUOCT2016) (CVE-2016-5598)
Summary: <dev-python/mysql-connector-python-2.1.4: Remote security vulnerability (CPUO...
Status: RESOLVED FIXED
Alias: CVE-2016-5598
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: http://www.oracle.com/technetwork/sec...
Whiteboard: ~1 [noglsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2016-10-19 16:31 UTC by Thomas Deutschmann (RETIRED)
Modified: 2016-11-20 03:52 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Thomas Deutschmann (RETIRED) gentoo-dev 2016-10-19 16:31:07 UTC
Oracle MySQL Connector is prone to a remote security vulnerability.

A remote user can exploit a flaw in the Connector/Python component to partially access data, partially modify data, and partially deny service.

This vulnerability affects the following supported versions:
2.1.3 and earlier, 2.0.4 and earlier.
Comment 1 Thomas Deutschmann (RETIRED) gentoo-dev 2016-10-19 16:36:10 UTC
@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 2 Mike Gilbert gentoo-dev 2016-11-19 18:06:07 UTC
I added mysql-connector-python-2.1.4 to the gentoo repo, and removed all older versions.

This package did not have any stable versions, so no need to stabilize anything here.
Comment 3 Thomas Deutschmann (RETIRED) gentoo-dev 2016-11-19 18:19:00 UTC
Thanks!


@ Security: Waiting for CVE than this can be closed.
Comment 4 GLSAMaker/CVETool Bot gentoo-dev 2016-11-20 03:52:21 UTC
CVE-2016-5598 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-5598):
  Unspecified vulnerability in the MySQL Connector component 2.1.3 and earlier
  and 2.0.4 and earlier in Oracle MySQL allows remote attackers to affect
  confidentiality, integrity, and availability via vectors related to
  Connector/Python.