From nobody Sat Jan 21 21:48:06 2023 X-Original-To: dev-commits-ports-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4Nzqjg2BKXz2v4tr; Sat, 21 Jan 2023 21:48:07 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4Nzqjg1fcDz3LTP; Sat, 21 Jan 2023 21:48:07 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1674337687; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=UbYDDQUOaJ2u+v8cKyq1y57obECWSMIzXjmmvBAyilM=; b=lhXLZkhhWF/UXtkKDrbGjTpBzedmesfvW2+ebt88Yq1xKi0NlybxTcOO+rEQQaSiDjtBE9 OmJUqNdl15foGq7UomYap54VjtnwSsxoCQxx2ZPLhwQdWoC3/TKX8L0ZULVwMwHSXKNsEd 4AVwNo6dDuPzzU+Fl6jHDwxLp54CO17ZQR+fKFrF5xdD4S1u4ppXF1FD65rF7UpxmDnxNJ wvjiq3VHzG7nAFojiiGixt8TSIfC5/nSQZNM48R2iYdFs7JgfQ/mKM6YEYlWTa8Gz9svOG pshnZQ9uNcIwWpwUZ1SECDrydmM5KFAnRj+NKXne4zr2dykDrw2m7AOrXKiA+Q== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1674337687; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=UbYDDQUOaJ2u+v8cKyq1y57obECWSMIzXjmmvBAyilM=; b=lEEiggfAd4RPXEhvr0YxQVShSQU6LGmKFLhNtbvDZDJ5HJJw4OYtJOu+TOaGA/El/fYB8D Fp+MZxdQ8Qe37xMmRglbAIe2nVmyGcEZSi2nHZ0H0Z8jqKNu8EQfrhwX7AjugKAa0eUc3i s1rqTDSF8lwL920V/KCzZ0ZJxf7slmhXeheOqJZbS1+O7JvwkNyjnwqiwZOdObRQhXm8u2 hHLnJvt1nXsdZmwFBUrPfuntSX0KcQEI8gJlytyEe3c+G1KwO//U68UmAeQF33p2/v97MB gnH28ULkuAJZc7tANQI7EoIWlP9g/q9LOcInc1X+JdiJ+kZYLVOmdUgvBZy+GA== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1674337687; a=rsa-sha256; cv=none; b=g8ORgaghc35INLQi/2Yd4N6qjqkHFELKH3MeDVX6AdfTG5LzVQO9kFxkOsi9vwxw0c81Wn QKk09aJ04GJX/jRYUX8W/SHm9oxVNcfCm9jN5T9IilPA0Ywc2wEp75yAjz/7aNqMplIYsx YpFYQ8et3ZlohZb0a8mG7Kq7W+IM/NR1oAJ+wcagl/sJfpsk2cbesDz3FI6Sir7CaiJoU2 Yw8+kcC5hVz0auam9yHZX+W6iJHNGxkZ9ZiOz5GMCxM0J8GPez3pD9+tswGC5Vs+ngzhgE G/mOaTyOCt+Se8s/OdgglQ5xHRLaseReebqSZ1P1tIHD1N8Sk7jtQx9mH7iLsQ== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4Nzqjg0XC0zQHQ; Sat, 21 Jan 2023 21:48:07 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.16.1/8.16.1) with ESMTP id 30LLm6Vs064895; Sat, 21 Jan 2023 21:48:06 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.16.1/8.16.1/Submit) id 30LLm6E0064894; Sat, 21 Jan 2023 21:48:06 GMT (envelope-from git) Date: Sat, 21 Jan 2023 21:48:06 GMT Message-Id: <202301212148.30LLm6E0064894@gitrepo.freebsd.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-main@FreeBSD.org From: Bernard Spil Subject: git: 0e9e18d9f290 - main - security/vuxml: Document 2023Q1 MySQL vulns List-Id: Commit messages for all branches of the ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-dev-commits-ports-all@freebsd.org X-BeenThere: dev-commits-ports-all@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: brnrd X-Git-Repository: ports X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: 0e9e18d9f290ec874112097ff62bcb1aaee0c9d4 Auto-Submitted: auto-generated X-ThisMailContainsUnwantedMimeParts: N The branch main has been updated by brnrd: URL: https://cgit.FreeBSD.org/ports/commit/?id=0e9e18d9f290ec874112097ff62bcb1aaee0c9d4 commit 0e9e18d9f290ec874112097ff62bcb1aaee0c9d4 Author: Bernard Spil AuthorDate: 2023-01-21 21:48:04 +0000 Commit: Bernard Spil CommitDate: 2023-01-21 21:48:04 +0000 security/vuxml: Document 2023Q1 MySQL vulns --- security/vuxml/vuln/2023.xml | 78 ++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 78 insertions(+) diff --git a/security/vuxml/vuln/2023.xml b/security/vuxml/vuln/2023.xml index 0b3ce493f241..30e741f00766 100644 --- a/security/vuxml/vuln/2023.xml +++ b/security/vuxml/vuln/2023.xml @@ -1,3 +1,81 @@ + + MySQL -- Multiple vulnerabilities + + + mysql-connector-c++ + 8.0.33 + + + mysql-connector-odbc + 8.0.33 + + + mysql-client57 + 5.7.42 + + + mysql-server57 + 5.7.42 + + + mysql-client80 + 8.0.33 + + + mysql-server80 + 8.0.33 + + + + +

Oracle reports:

+
+

This Critical Patch Update contains 37 new security patches for + Oracle MySQL. 8 of these vulnerabilities may be remotely exploitable + without authentication, i.e., may be exploited over a network withouti + requiring user credentials.

+
+ +
+ + CVE-2022-32221 + CVE-2022-24407 + CVE-2022-24407 + CVE-2022-3171 + CVE-2022-1941 + CVE-2023-21868 + CVE-2023-21860 + CVE-2023-21875 + CVE-2023-21869 + CVE-2023-21877 + CVE-2023-21880 + CVE-2023-21872 + CVE-2023-21871 + CVE-2023-21836 + CVE-2023-21887 + CVE-2023-21863 + CVE-2023-21864 + CVE-2023-21865 + CVE-2023-21866 + CVE-2023-21867 + CVE-2023-21870 + CVE-2023-21873 + CVE-2023-21876 + CVE-2023-21878 + CVE-2023-21879 + CVE-2023-21881 + CVE-2023-21883 + CVE-2023-21840 + CVE-2023-21882 + CVE-2023-21874 + https://www.oracle.com/security-alerts/cpujan2023.html#AppendixMSQL + + + 2023-01-20 + 2023-01-21 + +
+ phpmyfaq -- multiple vulnerabilities