MySQL: Multiple vulnerabilities — GLSA 201802-04

Multiple vulnerabilities were found in MySQL, the worst of which may allow remote execution of arbitrary code.

Affected packages

dev-db/mysql on all architectures
Affected versions < 5.6.39
Unaffected versions >= 5.6.39

Background

A fast, multi-threaded, multi-user SQL database server.

Description

Multiple vulnerabilities have been discovered in MySQL. Please review the referenced CVE identifiers for details.

Impact

A remote attacker could execute arbitrary code without authentication or cause a partial denial of service condition.

Workaround

There are no known workarounds at this time.

Resolution

All MySQL users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=dev-db/mysql-5.6.39"
 

References

Release date
February 20, 2018

Latest revision
February 20, 2018: 1

Severity
high

Exploitable
local, remote

Bugzilla entries