[ALSA-2020:5503] Moderate: mariadb-connector-c security, bug fix, and enhancement update
Type:
security
Severity:
moderate
Release date:
2020-12-15
Description:
The MariaDB Native Client library (C driver) is used to connect applications developed in C/C++ to MariaDB and MySQL databases. The following packages have been upgraded to a later upstream version: mariadb-connector-c (3.1.11). (BZ#1898993) Security Fix(es): * mysql: C API unspecified vulnerability (CPU Apr 2020) (CVE-2020-2752) * mysql: C API unspecified vulnerability (CPU Apr 2020) (CVE-2020-2922) * mariadb-connector-c: Improper validation of content in a OK packet received from server (CVE-2020-13249) * mysql: C API unspecified vulnerability (CPU Jan 2020) (CVE-2020-2574) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * Code utilizing plugins can't be compiled properly (BZ#1899001) * Add "zlib-devel" requirement in "-devel" subpackage (BZ#1899005) * Replace hard-coded /usr with %{_prefix} (BZ#1899099)
Updated packages:
  • mariadb-connector-c-3.1.11-2.el8_3.x86_64.rpm
  • mariadb-connector-c-3.1.11-2.el8_3.i686.rpm
  • mariadb-connector-c-config-3.1.11-2.el8_3.noarch.rpm
  • mariadb-connector-c-devel-3.1.11-2.el8_3.i686.rpm
  • mariadb-connector-c-devel-3.1.11-2.el8_3.x86_64.rpm
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.