--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2019-96516ce0ac
2019-09-04 04:05:05.597003
--------------------------------------------------------------------------------
Name : community-mysql
Product : Fedora 29
Version : 8.0.17
Release : 2.fc29
URL :
http://www.mysql.com
Summary : MySQL client programs and shared libraries
Description :
MySQL is a multi-user, multi-threaded SQL database server. MySQL is a
client/server implementation consisting of a server daemon (mysqld)
and many different client programs and libraries. The base package
contains the standard MySQL client programs and generic MySQL files.
--------------------------------------------------------------------------------
Update Information:
**MySQL 8.0.17** This update brings the latest MySQL 8.0.17 which fixes severe
security issues. Now available as both a standard package and a module! Release
notes:
https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-17.html
Mainatiner notes: * The MySQL Modules are now built from the same sources
as the base packages, so the should be identical * The package is now being
built with number of standard Fedora build flags that has not been used before.
The package should be now more stable and secure. * In Modules, the bug
#1729133 still exists * The MySQL 5.7 and 5.6 Modules may exists, but I'm
out of capacity to maintain them. Whenever possible upgrade to MySQL 8.
--------------------------------------------------------------------------------
ChangeLog:
* Mon Aug 19 2019 Michal Schorm <mschorm(a)redhat.com> - 8.0.17-2
- Use RELRO hardening on all binaries
* Wed Jul 31 2019 Lars Tangvald <lars.tangvald(a)oracle.com> - 8.0.17-1
- Update to MySQL 8.0.17
* Wed Jul 24 2019 Fedora Release Engineering <releng(a)fedoraproject.org> - 8.0.16-3
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild
* Wed May 1 2019 Michal Schorm <mschorm(a)redhat.com> - 8.0.16-2
- Remove SysVInit stuff, no longer needed
- Clean up the SPECfile
* Fri Apr 26 2019 Lars Tangvald <lars.tangvald(a)oracle.com> - 8.0.16-1
- Update to MySQL 8.0.16
- Rediff sharedir patch
- Refresh skip list and use new, required format
- Remove GCC9 patch now upstream
- Upstream: my_safe_process renamed and moved into proper location
- Use upstream option to skip router build
- OpenSSL 1.1.1 and TLSv1.3 is now supported, enable tests
- Update version of bundled Boost
- Start requiring mysql-selinux package
* Mon Feb 11 2019 Michal Schorm <mschorm(a)redhat.com> - 8.0.15-1
- Update to MySQL 8.0.15
* Thu Jan 31 2019 Fedora Release Engineering <releng(a)fedoraproject.org> - 8.0.14-3
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild
* Sun Jan 27 2019 Honza Horak <hhorak(a)redhat.com> - 8.0.14-2
- Use RPATH for mysqld, so we can later set capabilities
- Set capabilities for mysqld the correct way
* Mon Jan 21 2019 Lars Tangvald <lars.tangvald(a)oracle.com> - 8.0.14-1
- Update to MySQL 8.0.14
- Remove fedora version condition that are no longer relevant
- Update skipped tests list
- CVEs fixed: #1666778
CVE-2019-2420 CVE-2019-2434 CVE-2019-2436 CVE-2019-2455 CVE-2019-2481
CVE-2019-2482 CVE-2019-2486 CVE-2019-2494 CVE-2019-2495 CVE-2019-2502
CVE-2019-2503 CVE-2019-2507 CVE-2019-2510 CVE-2019-2528 CVE-2019-2529
CVE-2019-2530 CVE-2019-2531 CVE-2019-2532 CVE-2019-2533 CVE-2019-2534
CVE-2019-2535 CVE-2019-2536 CVE-2019-2537 CVE-2019-2539
* Wed Jan 16 2019 Michal Schorm <mschorm(a)redhat.com> - 8.0.13-3
- Tweak handling of the mysql-selinux requirement
* Mon Jan 14 2019 Bj��rn Esser <besser82(a)fedoraproject.org> - 8.0.13-2
- Rebuilt for libcrypt.so.2 (#1666033)
* Tue Oct 23 2018 Michal Schorm <mschorm(a)redhat.com> - 8.0.13-1
- Rebase to 8.0.13
- ICU patch removed; upstreamed
- Patch for MySQL Router introduced. Do not build it.
- CVEs fixed:
CVE-2018-3276 CVE-2018-3200 CVE-2018-3137 CVE-2018-3284 CVE-2018-3195
CVE-2018-3173 CVE-2018-3212 CVE-2018-3279 CVE-2018-3162 CVE-2018-3247
CVE-2018-3156 CVE-2018-3161 CVE-2018-3278 CVE-2018-3174 CVE-2018-3282
CVE-2018-3285 CVE-2018-3187 CVE-2018-3277 CVE-2018-3144 CVE-2018-3145
CVE-2018-3170 CVE-2018-3186 CVE-2018-3182 CVE-2018-3133 CVE-2018-3143
CVE-2018-3283 CVE-2018-3171 CVE-2018-3251 CVE-2018-3286 CVE-2018-3185
CVE-2018-3280 CVE-2018-3203 CVE-2018-3155
* Thu Sep 6 2018 Michal Schorm <mschorm(a)redhat.com> - 8.0.12-2
- Fix the SYS_NICE capabilities
Related: #1540946
- Add requires for the semanage binary
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1577199 - RFE: Ship selinux-policy in the package
https://bugzilla.redhat.com/show_bug.cgi?id=1577199
[ 2 ] Bug #1706923 - CVE-2019-2580 CVE-2019-2581 CVE-2019-2584 CVE-2019-2585
CVE-2019-2587 CVE-2019-2589 CVE-2019-2592 CVE-2019-2593 CVE-2019-2596 CVE-2019-2606
CVE-2019-2607 CVE-2019-2614 CVE-2019-2617 CVE-2019-2620 ... community-mysql: various flaws
[fedora-29]
https://bugzilla.redhat.com/show_bug.cgi?id=1706923
[ 3 ] Bug #1735044 - community-mysql: FTBFS in Fedora rawhide/f31
https://bugzilla.redhat.com/show_bug.cgi?id=1735044
[ 4 ] Bug #1732044 - CVE-2019-2737 CVE-2019-2738 CVE-2019-2739 CVE-2019-2740
CVE-2019-2752 CVE-2019-2755 CVE-2019-2757 CVE-2019-2758 CVE-2019-2774 CVE-2019-2778
CVE-2019-2780 CVE-2019-2784 CVE-2019-2785 CVE-2019-2789 ... community-mysql: various flaws
[fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1732044
[ 5 ] Bug #1742172 - community-mysql-8.0.17 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1742172
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2019-96516ce0ac' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------