Errata overview
Errata ID 382
Date 2018-05-08
Source package mysql-5.5
Fixed in version 5.5.60-0+deb8u1A~4.2.3.201804221415
Description
Multiple security issues have been fixed since MySQL 5.5.59.
Since Oracle does not disclose sufficient information to provide backported
patches, MySQL is updated to the new release.
* https://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-60.html
* http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
This update addresses the following issues:
* Difficult to exploit vulnerability allows unauthenticated attacker with
  logon to the infrastructure where MySQL Server executes to compromise MySQL
  Server. Successful attacks of this vulnerability can result in takeover of
  MySQL Server. (CVE-2018-2755)
* Difficult to exploit vulnerability allows unauthenticated attacker with
  network access via multiple protocols to compromise MySQL Server.
  Successful attacks of this vulnerability can result in unauthorized ability
  to cause a hang or frequently repeatable crash (complete DOS) of MySQL
  Server. (CVE-2018-2761)
* Easily exploitable vulnerability allows low privileged attacker with
  network access via multiple protocols to compromise MySQL Server.
  Successful attacks of this vulnerability can result in unauthorized ability
  to cause a hang or frequently repeatable crash (complete DOS) of MySQL
  Server. (CVE-2018-2819)
* Easily exploitable vulnerability allows high privileged attacker with
  network access via multiple protocols to compromise MySQL Server.
  Successful attacks of this vulnerability can result in unauthorized ability
  to cause a hang or frequently repeatable crash (complete DOS) of MySQL
  Server. (CVE-2018-2818)
* Easily exploitable vulnerability allows low privileged attacker with
  network access via multiple protocols to compromise MySQL Server.
  Successful attacks of this vulnerability can result in unauthorized ability
  to cause a hang or frequently repeatable crash (complete DOS) of MySQL
  Server. (CVE-2018-2817)
* Easily exploitable vulnerability allows low privileged attacker with
  network access via multiple protocols to compromise MySQL Server.
  Successful attacks of this vulnerability can result in unauthorized read
  access to a subset of MySQL Server accessible data. (CVE-2018-2813)
* Difficult to exploit vulnerability allows high privileged attacker with
  network access via multiple protocols to compromise MySQL Server.
  Successful attacks of this vulnerability can result in unauthorized ability
  to cause a hang or frequently repeatable crash (complete DOS) of MySQL
  Server. (CVE-2018-2771)
* Difficult to exploit vulnerability allows high privileged attacker with
  logon to the infrastructure where MySQL Server executes to compromise MySQL
  Server. Successful attacks of this vulnerability can result in unauthorized
  ability to cause a hang or frequently repeatable crash (complete DOS) of
  MySQL Server. (CVE-2018-2773)
* Easily exploitable vulnerability allows high privileged attacker with
  network access via multiple protocols to compromise MySQL Server.
  Successful attacks of this vulnerability can result in unauthorized ability
  to cause a hang or frequently repeatable crash (complete DOS) of MySQL
  Server. (CVE-2018-2781)
Additional notes
CVE ID CVE-2018-2755
CVE-2018-2761
CVE-2018-2819
CVE-2018-2818
CVE-2018-2817
CVE-2018-2813
CVE-2018-2771
CVE-2018-2773
CVE-2018-2781
UCS Bug number #46865