Debian Security Advisory

DLA-819-2 mysql-5.5 -- LTS security update

Date Reported:
10 Feb 2017
Affected Packages:
mysql-5.5
Vulnerable:
Yes
Security database references:
No other external database security references currently available.
More information:

This is a correction of DLA 819-1 that mentioned that mysql-5.5 5.5.47-0+deb7u2 was corrected. The corrected package version was 5.5.54-0+deb7u2.

For completeness the text from DLA 819-1 is available below with only corrected version information. No other changes.

It has been found that the C client library for MySQL (libmysqlclient.so) has use-after-free vulnerability which can cause crash of applications using that MySQL client.

For Debian 7 Wheezy, these problems have been fixed in version 5.5.54-0+deb7u2.

We recommend that you upgrade your mysql-5.5 packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS