Overview

Request 288038 accepted

percona-toolkit and xtrabackup were updated to fix one vulnerability and several bugs.

The following security issues were fixed:

CVE-2015-1027 (boo#919298) Both packages were vulnerable to a man-in-the-middle attack which would allow exfiltration of MySQL configuration --version-check. They did not sufficiently verify a server certificate for validity.

The version check is disabled by default in openSUSE packages.

On openSUSE 13.1 and 13.2, Percona Toolkit was updated to 2.2.13 to fix a number of bugs.

On openSUSE 13.2, XtraBackup was updated to 2.2.9 to add improvements and bug fixes.

Request History
Andreas Stieger's avatar

AndreasStieger created request

percona-toolkit and xtrabackup were updated to fix one vulnerability and several bugs.

The following security issues were fixed:

CVE-2015-1027 (boo#919298) Both packages were vulnerable to a man-in-the-middle attack which would allow exfiltration of MySQL configuration --version-check. They did not sufficiently verify a server certificate for validity.

The version check is disabled by default in openSUSE packages.

On openSUSE 13.1 and 13.2, Percona Toolkit was updated to 2.2.13 to fix a number of bugs.

On openSUSE 13.2, XtraBackup was updated to 2.2.9 to add improvements and bug fixes.


Maintenance Bot's avatar

maintbot accepted review

accepted


Maintenance Bot's avatar

maintbot approved review

accepted


Marcus Meissner's avatar

msmeissn moved maintenance target to openSUSE:Maintenance:3587


Marcus Meissner's avatar

msmeissn accepted request

ok

openSUSE Build Service is sponsored by