--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2019-c1fab3f139
2019-11-11 17:39:30.878699
--------------------------------------------------------------------------------
Name : community-mysql
Product : Fedora 29
Version : 8.0.18
Release : 1.fc29
URL :
http://www.mysql.com
Summary : MySQL client programs and shared libraries
Description :
MySQL is a multi-user, multi-threaded SQL database server. MySQL is a
client/server implementation consisting of a server daemon (mysqld)
and many different client programs and libraries. The base package
contains the standard MySQL client programs and generic MySQL files.
--------------------------------------------------------------------------------
Update Information:
**MySQL 8.0.18** Release notes:
https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-18.html CVEs fixed:
CVE-2019-2911 CVE-2019-2914 CVE-2019-2938 CVE-2019-2946 CVE-2019-2957
CVE-2019-2960 CVE-2019-2963 CVE-2019-2966 CVE-2019-2967 CVE-2019-2968
CVE-2019-2974 CVE-2019-2982 CVE-2019-2991 CVE-2019-2993 CVE-2019-2997
CVE-2019-2998 CVE-2019-3004 CVE-2019-3009 CVE-2019-3011 CVE-2019-3018
https://bugzilla.redhat.com/show_bug.cgi?id=1768175
https://www.oracle.com/security-alerts/cpuoct2019.html Maintainer notes:
linking with GOLD disabled on armv7hl, because of
https://bugs.mysql.com/bug.php?id=96698
--------------------------------------------------------------------------------
ChangeLog:
* Mon Oct 14 2019 Lars Tangvald <lars.tangvald(a)oracle.com> - 8.0.18-1
- Update to MySQL 8.0.18
* Mon Aug 19 2019 Michal Schorm <mschorm(a)redhat.com> - 8.0.17-2
- Use RELRO hardening on all binaries
* Wed Jul 31 2019 Lars Tangvald <lars.tangvald(a)oracle.com> - 8.0.17-1
- Update to MySQL 8.0.17
* Wed Jul 24 2019 Fedora Release Engineering <releng(a)fedoraproject.org> - 8.0.16-3
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild
* Wed May 1 2019 Michal Schorm <mschorm(a)redhat.com> - 8.0.16-2
- Remove SysVInit stuff, no longer needed
- Clean up the SPECfile
* Fri Apr 26 2019 Lars Tangvald <lars.tangvald(a)oracle.com> - 8.0.16-1
- Update to MySQL 8.0.16
- Rediff sharedir patch
- Refresh skip list and use new, required format
- Remove GCC9 patch now upstream
- Upstream: my_safe_process renamed and moved into proper location
- Use upstream option to skip router build
- OpenSSL 1.1.1 and TLSv1.3 is now supported, enable tests
- Update version of bundled Boost
- Start requiring mysql-selinux package
* Mon Feb 11 2019 Michal Schorm <mschorm(a)redhat.com> - 8.0.15-1
- Update to MySQL 8.0.15
* Thu Jan 31 2019 Fedora Release Engineering <releng(a)fedoraproject.org> - 8.0.14-3
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild
* Sun Jan 27 2019 Honza Horak <hhorak(a)redhat.com> - 8.0.14-2
- Use RPATH for mysqld, so we can later set capabilities
- Set capabilities for mysqld the correct way
* Mon Jan 21 2019 Lars Tangvald <lars.tangvald(a)oracle.com> - 8.0.14-1
- Update to MySQL 8.0.14
- Remove fedora version condition that are no longer relevant
- Update skipped tests list
- CVEs fixed: #1666778
CVE-2019-2420 CVE-2019-2434 CVE-2019-2436 CVE-2019-2455 CVE-2019-2481
CVE-2019-2482 CVE-2019-2486 CVE-2019-2494 CVE-2019-2495 CVE-2019-2502
CVE-2019-2503 CVE-2019-2507 CVE-2019-2510 CVE-2019-2528 CVE-2019-2529
CVE-2019-2530 CVE-2019-2531 CVE-2019-2532 CVE-2019-2533 CVE-2019-2534
CVE-2019-2535 CVE-2019-2536 CVE-2019-2537 CVE-2019-2539
* Wed Jan 16 2019 Michal Schorm <mschorm(a)redhat.com> - 8.0.13-3
- Tweak handling of the mysql-selinux requirement
* Mon Jan 14 2019 Bj��rn Esser <besser82(a)fedoraproject.org> - 8.0.13-2
- Rebuilt for libcrypt.so.2 (#1666033)
* Tue Oct 23 2018 Michal Schorm <mschorm(a)redhat.com> - 8.0.13-1
- Rebase to 8.0.13
- ICU patch removed; upstreamed
- Patch for MySQL Router introduced. Do not build it.
- CVEs fixed:
CVE-2018-3276 CVE-2018-3200 CVE-2018-3137 CVE-2018-3284 CVE-2018-3195
CVE-2018-3173 CVE-2018-3212 CVE-2018-3279 CVE-2018-3162 CVE-2018-3247
CVE-2018-3156 CVE-2018-3161 CVE-2018-3278 CVE-2018-3174 CVE-2018-3282
CVE-2018-3285 CVE-2018-3187 CVE-2018-3277 CVE-2018-3144 CVE-2018-3145
CVE-2018-3170 CVE-2018-3186 CVE-2018-3182 CVE-2018-3133 CVE-2018-3143
CVE-2018-3283 CVE-2018-3171 CVE-2018-3251 CVE-2018-3286 CVE-2018-3185
CVE-2018-3280 CVE-2018-3203 CVE-2018-3155
* Thu Sep 6 2018 Michal Schorm <mschorm(a)redhat.com> - 8.0.12-2
- Fix the SYS_NICE capabilities
Related: #1540946
- Add requires for the semanage binary
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1761354 - community-mysql-8.0.18 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1761354
[ 2 ] Bug #1768175 - CVE-2019-2911 CVE-2019-2914 CVE-2019-2938 CVE-2019-2946
CVE-2019-2957 CVE-2019-2960 CVE-2019-2963 CVE-2019-2966 CVE-2019-2967 CVE-2019-2968
CVE-2019-2974 CVE-2019-2982 CVE-2019-2991 CVE-2019-2993 ... community-mysql: various flaws
[fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1768175
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2019-c1fab3f139' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------