-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2919-1 security@debian.org http://www.debian.org/security/ Salvatore Bonaccorso May 03, 2014 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : mysql-5.5 CVE ID : CVE-2014-0001 CVE-2014-0384 CVE-2014-2419 CVE-2014-2430 CVE-2014-2431 CVE-2014-2432 CVE-2014-2436 CVE-2014-2438 CVE-2014-2440 Debian Bug : 737596 744910 Several issues have been discovered in the MySQL database server. The vulnerabilities are addressed by upgrading MySQL to the new upstream version 5.5.37. Please see the MySQL 5.5 Release Notes and Oracle's Critical Patch Update advisory for further details: http://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-36.html http://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-37.html http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html For the stable distribution (wheezy), these problems have been fixed in version 5.5.37-0+wheezy1. For the testing distribution (jessie), these problems have been fixed in version 5.5.37-1. For the unstable distribution (sid), these problems have been fixed in version 5.5.37-1. We recommend that you upgrade your mysql-5.5 packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCgAGBQJTZKMTAAoJEAVMuPMTQ89EEjwP/RnbHaJeN9D/0HcqRjDFsN/a 3I6WlLAebdW9jJDX5y+ynJ/dMPx9uzQcmACmzYGl8LNbUaqGiCyiBhpVI0jGXzql FaPR79uaKtqEOFZIpw0a+fwc7J85/Q7kid6201csAWvij02gEkw07ddQP4MbZlC/ Z87eosw070HwJqVYEkZTaK+9sae+U2LhfjaLaXsRdphn5SN0f0m8vAKUggEmuERI GxXLSEojDr0GeCwlUgKiu7jbizmNOOBfHWm/0tXhsGev9vkWVv2va9Zr0J5gcTM/ B2NcGSPkbGmDo0qaltL9R0YA0nbM85z1h4ABkT8ckEhT7i9MHXfc4n2OWcB1uV3G K/1iFWD61nHPfFqXfoYMDNEAuykJnxB2aNnAWZfo59Er0kUCO/8cPLfwaoL6IUzO h/8xEtcHKvH7Uqx9Hme23z4oDwYoUVfcQQd08alEsA6FVU4JEuGXxLFiJufcs2bj G2kcLXWQDYe+w+qyLYtTKu7iHDxXbyksIcQ7mdAf9kPzSvB1SROojbuWQBjp4UQ+ Qrw/n72EmJj3fgHkJU1VdAS4OtNfdZLSM9vooTmJrp7tjIuXhAzFimDy7nuNbcb4 TtRSnSwrJ0FWoxk94uwggPK5XIoPQ7d0u6ohBXGkhQp298gIDnx+fsHvsslRyQss o4v6AdSgotKNV/oYEuyb =g7vR -----END PGP SIGNATURE-----