Your message dated Sat, 27 May 2017 23:48:41 +0000
with message-id <[email protected]>
and subject line Bug#861511: fixed in mysql-connector-python 2.1.6-1
has caused the Debian Bug report #861511,
regarding mysql-connector-python: CVE-2017-3590
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
861511: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=861511
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: mysql-connector-python
Version: 2.1.5-1
Severity: important
Tags: upstream security
Hi,
the following vulnerability was published for mysql-connector-python.
CVE-2017-3590[0]:
| Vulnerability in the MySQL Connectors component of Oracle MySQL
| (subcomponent: Connector/Python). Supported versions that are affected
| are 2.1.5 and earlier. Easily "exploitable" vulnerability allows low
| privileged attacker with logon to the infrastructure where MySQL
| Connectors executes to compromise MySQL Connectors. Successful attacks
| of this vulnerability can result in unauthorized update, insert or
| delete access to some of MySQL Connectors accessible data. CVSS 3.0
| Base Score 3.3 (Integrity impacts). CVSS Vector:
| (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).
According to the Oracle advisory fixed in 2.1.6.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2017-3590
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3590
[1] http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: mysql-connector-python
Source-Version: 2.1.6-1
We believe that the bug you reported is fixed in the latest version of
mysql-connector-python, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Sandro Tosi <[email protected]> (supplier of updated mysql-connector-python
package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Sat, 27 May 2017 19:25:45 -0400
Source: mysql-connector-python
Binary: python-mysql.connector python3-mysql.connector
Architecture: source all
Version: 2.1.6-1
Distribution: unstable
Urgency: medium
Maintainer: Sandro Tosi <[email protected]>
Changed-By: Sandro Tosi <[email protected]>
Description:
python-mysql.connector - pure Python implementation of MySQL Client/Server
protocol
python3-mysql.connector - pure Python implementation of MySQL Client/Server
protocol (Pytho
Closes: 861511
Changes:
mysql-connector-python (2.1.6-1) unstable; urgency=medium
.
* New upstream release
- fixes CVE-2017-3590; Closes: #861511
* debian/copyright
- extend upstream copyright years
- update packaging copyright years
Checksums-Sha1:
44744e7269e8f8b10ecf683532d4ee2067928465 2326
mysql-connector-python_2.1.6-1.dsc
77a49a709a8204863811e3eacb04f13c2be7caa0 11777023
mysql-connector-python_2.1.6.orig.tar.gz
976442f0e2e8ee39f3ce659532c56c5aad9a14ce 4572
mysql-connector-python_2.1.6-1.debian.tar.xz
601667444a5409c8aa9c75ec5b467ff94fa016a3 7423
mysql-connector-python_2.1.6-1_amd64.buildinfo
c5ade5867160f53caf2db8266c022acdb8afc364 100384
python-mysql.connector_2.1.6-1_all.deb
ff1069aa236a8013b842c1114f9c5dd958bc047e 100458
python3-mysql.connector_2.1.6-1_all.deb
Checksums-Sha256:
174fc47cecfea7d2a8f51d83a0b494e636dc3505cfe5e1825ef9096b1eaeba6a 2326
mysql-connector-python_2.1.6-1.dsc
d5f7e77bec937d50d2dc62c751e7470caa8d21fec9a3305856dd58705c62df99 11777023
mysql-connector-python_2.1.6.orig.tar.gz
ce93928c18361f41465832c722a363f48309358a46251db6a886ca62adb5b751 4572
mysql-connector-python_2.1.6-1.debian.tar.xz
183b9b353ece56b1a3dfa244ffe66a94ec6dd340e56dc239fe3f03b652067577 7423
mysql-connector-python_2.1.6-1_amd64.buildinfo
aaeebac35d464a0c7eb4b6cb96d8250c5c213c109ea56077077cf650448aa9cf 100384
python-mysql.connector_2.1.6-1_all.deb
f17c1184852c5bea24806843edc31f93276f47775adf0ae8c12c4edcd25c7dca 100458
python3-mysql.connector_2.1.6-1_all.deb
Files:
769db32ca4fc8824d292f21e804c7796 2326 python optional
mysql-connector-python_2.1.6-1.dsc
32fddb04b0d2840303d92040c394504c 11777023 python optional
mysql-connector-python_2.1.6.orig.tar.gz
53f228ca3931ad92832c538a904f440a 4572 python optional
mysql-connector-python_2.1.6-1.debian.tar.xz
b4e6ea522e811eaf8ef9db48fd1b5243 7423 python optional
mysql-connector-python_2.1.6-1_amd64.buildinfo
440f88b1d3765eef97b2a11744a2e5d5 100384 python optional
python-mysql.connector_2.1.6-1_all.deb
573694125544bd33fc13eaaab5b063e3 100458 python optional
python3-mysql.connector_2.1.6-1_all.deb
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCAAdFiEEufrTGSrz5KUwnZ05h588mTgBqU8FAlkqC+IACgkQh588mTgB
qU/AHRAAtHfrlB1SU0/1gZ5iCHIrziB20ArPKYHVL8hrMjOZDhs62Be7OG7F+YDM
H2k/LK2YinrRxKFtk+Ti9m3sJyLNRs4d0Gi+9141wmTSmD6RRGwt77hipdxupkgW
KL5Ea+VhCglEpydnKwXmOcUPaJ0M8B/BFHbBedjAe+p1dCH4Joe8qXMBEP58hddf
T1ZOdzuJtP+u+LwegQN9nXh3QPLQCBHbkbM81M0N5eYyk/qQHj9gi9nDgOdx6Cnr
ypjIjYbz0TzM3H0Nuby4TMvHGQ314axzdvMo6UGjGgYV7SXFPuhoJKOb4fkFvEnk
Jv+9n2772MCiKc53AOwo10yqzjTnVNgiDpZlIKdwRTuYNBxSmVUmarXzlVj8OGnq
LTyosPLs+JU7/XoOGhNBqRHZojX/hwLCUzIVKLbWNPmakKDlicNTS9mb2Ix8tuY1
Z2F9RM6IWk9fwIA5uFOjqXBg+/3RSNciKiEC3n+c4HvYlhnhhQGB3prhnKcHFLxF
+zvsa/CfDRJ1hfy6XLTOYsjuaaO1Tphi3Vm3XlpdzDadf1ndUTkEJH4KiyZ8lvNy
Dgwd3KNOC22sCX83ZmUFDQ21HhVNFMp38ZxDes8+BxdnRnQkevaTMrAf12aZHSto
nKj1LQvqL4Fh37YhfOiDvBPdfEVfsopf7N+etnsPc0ecDOvyH5w=
=8JLU
-----END PGP SIGNATURE-----
--- End Message ---