{
  "schema_version": "1.7.0",
  "id": "MGASA-2020-0345",
  "published": "2020-08-25T08:13:25Z",
  "modified": "2020-08-25T07:41:38Z",
  "summary": "Updated mysql-connector-python packages fix security vulnerability",
  "details": "Easily exploitable vulnerability allows unauthenticated attacker with network\naccess via TLS to compromise MySQL Connectors. Successful attacks require human\ninteraction from a person other than the attacker. Successful attacks of this\nvulnerability can result in unauthorized creation, deletion or modification\naccess to critical data or all MySQL Connectors accessible data as well as\nunauthorized access to critical data or complete access to all MySQL Connectors\naccessible data (CVE-2019-2435).\n\nAlso, the protobuf package was updated to add a python3 subpackage, which was\nneeded for this update.\n",
  "upstream": [
    "CVE-2019-2435"
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://advisories.mageia.org/MGASA-2020-0345.html"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.mageia.org/show_bug.cgi?id=26402"
    },
    {
      "type": "ADVISORY",
      "url": "http://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html#CVE-2019-2435"
    },
    {
      "type": "WEB",
      "url": "https://lists.opensuse.org/opensuse-updates/2020-03/msg00140.html"
    }
  ],
  "affected": [
    {
      "package": {
        "ecosystem": "Mageia:7",
        "name": "protobuf",
        "purl": "pkg:rpm/mageia/protobuf?arch=source&distro=mageia-7"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "3.6.1-1.1.mga7"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:7",
        "name": "mysql-connector-python",
        "purl": "pkg:rpm/mageia/mysql-connector-python?arch=source&distro=mageia-7"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "8.0.20-1.mga7"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    }
  ],
  "credits": [
    {
      "name": "Mageia",
      "type": "COORDINATOR",
      "contact": [
        "https://wiki.mageia.org/en/Packages_Security_Team"
      ]
    }
  ]
}
