Red Hat released MySQL security updates for Red Hat Enterprise Linux and Red Hat Software Collections, upgrading mysql55-mysql to 5.5.45 and rh-mysql56-mysql to 5.6.26. The advisories incorporate fixes from Oracle’s January, April, and July 2015 Critical Patch Updates, remediating 15 CVEs in the MySQL 5.5 Software Collections stream and 18 CVEs in the MySQL 5.6 stream; Red Hat rated the 5.5 updates Moderate and the 5.6 update Important.
The flaws include unauthenticated network denial of service in replication (CVE-2015-0382), authenticated unauthorized read access through the security-privileges component (CVE-2015-2620), and authenticated denial-of-service conditions in DML, Optimizer, DDL, and InnoDB foreign-key processing, including CVE-2015-2648, CVE-2015-2643, CVE-2015-0505, and CVE-2015-0432. Affected systems should apply the relevant packages; the mysqld service restarts automatically after installation.

See real exploitation activity before you spend the cycle.
35 events from the most recent confirmed update back to the earliest known activity.
Red Hat began remediating the authenticated MySQL Server Federated availability flaw CVE-2015-0499 through RHSA-2015:1628 and RHSA-2015:1629 on August 17, 2015. It subsequently issued fixes for Software Collections MariaDB through RHSA-2015:1646 and RHSA-2015:1647 and for RHEL 7 MariaDB through RHSA-2015:1665.
Red Hat began fixing the MySQL Server Optimizer availability flaw CVE-2015-4757 on August 17, 2015, through RHSA-2015:1628, RHSA-2015:1629, and RHSA-2015:1630 for RHEL 5 and Software Collections MySQL packages. Further fixes covered Software Collections MariaDB packages on August 20 and RHEL 7 MariaDB through RHSA-2015:1665 on August 24.
Red Hat began remediating CVE-2015-4864, an authenticated remote MySQL Server Security: Privileges flaw affecting MySQL 5.5.43 and earlier and 5.6.24 and earlier, through RHSA-2015:1628, RHSA-2015:1629, and RHSA-2015:1630. Further fixes for Software Collections MariaDB and RHEL 7 MariaDB followed in August 2015.
Red Hat fixed CVE-2015-0441 in RHEL 5 mysql55-mysql through RHSA-2015:1628 on August 17, 2015. The authenticated remote MySQL Server Security: Encryption flaw affected MySQL 5.5.41 and earlier and 5.6.22 and earlier and could affect server availability.
Red Hat began issuing errata for CVE-2015-4737 on August 17, 2015, including RHSA-2015:1628, RHSA-2015:1629, and RHSA-2015:1630 for affected RHEL 5 and Software Collections MySQL packages. Subsequent August advisories fixed affected MariaDB packages in Software Collections and RHEL 7.
Red Hat remediated CVE-2015-2571 in RHEL 6 Software Collections mysql55-mysql through RHSA-2015:1629, followed by rh-mariadb100-mariadb and mariadb55-mariadb fixes in RHSA-2015:1646 and RHSA-2015:1647. RHEL 7 mariadb was subsequently fixed through RHSA-2015:1665.
Red Hat fixed CVE-2015-2582 in RHEL 6 Software Collections mysql55-mysql and rh-mysql56-mysql through RHSA-2015:1629 and RHSA-2015:1630 on August 17, 2015. It subsequently remediated the MySQL GIS availability flaw in Software Collections MariaDB through RHSA-2015:1646 and RHSA-2015:1647 and RHEL 7 MariaDB through RHSA-2015:1665.
Red Hat's RHSA-2015:1628 update for RHEL 5 mysql55-mysql packages remediated CVE-2015-2571, a MySQL Server Optimizer vulnerability, and CVE-2015-2582, a MySQL Server GIS vulnerability. The advisory upgraded MySQL to 5.5.45.
Red Hat began fixing CVE-2015-0505 in RHEL 5 mysql55-mysql and RHEL 6 Software Collections mysql55-mysql through RHSA-2015:1628 and RHSA-2015:1629 on August 17, 2015. It subsequently remediated the authenticated MySQL DDL availability flaw in Software Collections MariaDB packages through RHSA-2015:1646 and RHSA-2015:1647 and in RHEL 7 mariadb through RHSA-2015:1665.
Red Hat published Moderate-severity advisory RHSA-2015:1628 for RHEL 5, updating mysql55-mysql packages to version 5.5.45. The update addressed multiple MySQL Server vulnerabilities from Oracle's 2015 Critical Patch Updates, including CVE-2015-0382, CVE-2015-0432, CVE-2015-0505, CVE-2015-2620, CVE-2015-2643, and CVE-2015-2648.
Red Hat issued RHSA-2015:1629 and RHSA-2015:1630 for Red Hat Software Collections 2, updating MySQL 5.5 to 5.5.45 and MySQL 5.6 to 5.6.26. The updates remediated multiple MySQL vulnerabilities, including CVE-2015-2620, CVE-2015-2643, and CVE-2015-2648.
Oracle disclosed CVE-2015-4757, a difficult-to-exploit authenticated remote vulnerability in the MySQL Server Optimizer component. Attackers using multiple protocols could hang or repeatedly crash affected MySQL servers, causing complete denial of service.
Oracle disclosed CVE-2015-2648 on July 20, 2015. An authenticated network attacker could exploit the Server DML flaw to hang or repeatedly crash affected MySQL servers, causing complete denial of service.
Oracle documented CVE-2015-4752 in its July 2015 Critical Patch Update. The authenticated remote MySQL Server:I_S vulnerability affected MySQL 5.5.43 and earlier and 5.6.24 and earlier, allowing attackers using multiple protocols to hang or repeatedly crash servers and cause complete denial of service; Red Hat addressed it in advisories including RHSA-2015:1628, RHSA-2015:1629, RHSA-2015:1630, RHSA-2015:1646, RHSA-2015:1647, and RHSA-2015:1665.
Oracle referenced CVE-2015-4737 in its July 2015 Critical Patch Update. The difficult-to-exploit, authenticated network flaw in MySQL Server Pluggable Authentication affected versions 5.5.43 and earlier and 5.6.23 and earlier, allowing unauthorized read access to a subset of accessible MySQL data.
Oracle documented CVE-2015-2620, which could permit unauthorized read access to a subset of MySQL-accessible data, and CVE-2015-2643, which could cause MySQL denial of service, in its July 2015 Critical Patch Update.
Oracle's April 2015 Critical Patch Update included CVE-2015-0499, a difficult-to-exploit authenticated network vulnerability in MySQL Server:Federated affecting MySQL 5.5.42 and earlier and 5.6.23 and earlier. Exploitation through multiple protocols could hang or repeatedly crash MySQL Server, causing complete denial of service; Fedora, Red Hat, and MariaDB issued fixes.
Oracle's April 2015 Critical Patch Update covered CVE-2015-2568, an unauthenticated remotely exploitable MySQL Server Security Privileges flaw affecting versions 5.5.41 and earlier and 5.6.22 and earlier. Attackers using multiple protocols could hang or repeatedly crash MySQL Server, causing complete denial of service; Fedora, Red Hat, and MariaDB issued fixes.
Oracle documented CVE-2015-0501 in its April 2015 Critical Patch Update. The remotely exploitable, difficult-to-exploit Server Compiling flaw affected MySQL 5.5.42 and earlier and 5.6.23 and earlier; authenticated attackers could cause an operating-system hang or repeatable complete denial of service.
Oracle referenced CVE-2015-0433 in its April 2015 Critical Patch Update. The authenticated remote InnoDB DML vulnerability affected MySQL 5.5.41 and earlier and 5.6.22 and earlier, allowing attackers to hang or repeatedly crash the server and cause denial of service.
Oracle documented CVE-2015-2573 in its April 2015 Critical Patch Update. The authenticated remote Server DDL vulnerability affected MySQL 5.5.41 and earlier and 5.6.22 and earlier, allowing attackers to hang or repeatedly crash MySQL Server and cause complete denial of service.
Oracle's April 2015 Critical Patch Update covered CVE-2015-0505, an authenticated network-accessible MySQL Server DDL flaw that could hang or repeatedly crash affected servers.
Red Hat fixed CVE-2015-0411 in RHEL 7 MariaDB through RHSA-2015:0118 on February 3, 2015. Subsequent April and August advisories remediated the unauthenticated remote MySQL Server encryption vulnerability in OpenStack Platform 5.0 and RHEL 5 mysql55-mysql packages.
Red Hat fixed CVE-2015-0374 in RHEL 7 MariaDB through RHSA-2015:0118 on February 3, 2015. It subsequently addressed the flaw in OpenStack Platform 5.0 through RHBA-2015:0820 and RHBA-2015:0825 in April 2015 and in RHEL 5 mysql55-mysql through RHSA-2015:1628 on August 17, 2015.
Oracle documented CVE-2015-0381 in its January 2015 Critical Patch Update. The difficult-to-exploit unauthenticated remote MySQL Server Replication vulnerability affected MySQL 5.5.40 and earlier and 5.6.21 and earlier, allowing attackers to hang or repeatedly crash servers and cause complete denial of service; Red Hat issued fixes in RHSA-2015:0116, RHSA-2015:0117, and RHSA-2015:0118.
Oracle referenced CVE-2014-6568 in its January 2015 Critical Patch Update. The difficult-to-exploit authenticated remote flaw in MySQL Server InnoDB DML affected MySQL 5.5.40 and earlier and 5.6.21 and earlier and could hang the server or cause repeatable complete denial of service.
Oracle documented CVE-2015-0391 in its January 2015 Critical Patch Update. The authenticated, remotely exploitable MySQL Server DDL flaw affected versions 5.5.38 and earlier and 5.6.19 and earlier, allowing attackers to hang or repeatedly crash the server and cause complete denial of service.
Oracle documented CVE-2015-0374 in its January 2015 Critical Patch Update. The difficult-to-exploit authenticated network vulnerability in MySQL foreign-key privilege handling affected MySQL 5.5.40 and earlier and 5.6.21 and earlier, allowing unauthorized read access to a subset of MySQL-accessible data.
Oracle referenced CVE-2015-0382, a remotely exploitable unauthenticated replication denial-of-service flaw, and CVE-2015-0432, an authenticated InnoDB DDL foreign-key denial-of-service flaw, in its January 2015 Critical Patch Update.
Red Hat fixed CVE-2015-2568 in RHEL 7 MariaDB through RHSA-2015:1665 on August 24, 2015. It also remediated the flaw in RHEL OpenStack Platform 5.0 packages through RHBA-2015:1762 and RHBA-2015:1763 on September 10, 2015.
Red Hat issued RHBA-2015:1762 for RHEL 7 and RHBA-2015:1763 for RHEL 6 OpenStack Platform 5.0, addressing CVE-2015-2573 in affected MariaDB-Galera and related OpenStack packages.
Red Hat issued RHSA-2015:1665 for Red Hat Enterprise Linux 7, fixing CVE-2015-0433 in the mariadb component. The flaw allowed an authenticated remote attacker to cause a partial denial of service through MySQL InnoDB DML functionality.
Red Hat remediated CVE-2015-2648 in Red Hat Software Collections for RHEL 6 MariaDB packages through RHSA-2015:1646 and RHSA-2015:1647. The authenticated remote MySQL DML flaw could partially affect server availability.
Red Hat fixed CVE-2015-2643 in Software Collections rh-mariadb100-mariadb and mariadb55-mariadb through RHSA-2015:1646 and RHSA-2015:1647 on August 20, 2015. It subsequently remediated the MySQL Server Optimizer denial-of-service flaw in RHEL 7 mariadb through RHSA-2015:1665 on August 24, 2015.
Red Hat remediated CVE-2015-2620 in Software Collections rh-mariadb100-mariadb and mariadb55-mariadb packages through RHSA-2015:1646 and RHSA-2015:1647 on August 20, 2015. It subsequently fixed the MySQL Security: Privileges confidentiality flaw in RHEL 7 mariadb through RHSA-2015:1665 on August 24, 2015.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
44 references tracked. Mallory keeps watching after this page renders.
rhn.redhat.com
Open sourceaccess.redhat.com
Open sourcerhn.redhat.com
Open sourcerhn.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.