Your message dated Sun, 27 Oct 2024 21:57:48 +0000
with message-id <[email protected]>
and subject line Bug#1085297: fixed in mysql-connector-python 9.1.0-1
has caused the Debian Bug report #1085297,
regarding mysql-connector-python: CVE-2024-21272
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1085297: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1085297
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: mysql-connector-python
X-Debbugs-CC: [email protected]
Severity: important
Tags: security

Hi,

The following vulnerability was published for mysql-connector-python.

CVE-2024-21272[0]:
| Vulnerability in the MySQL Connectors product of Oracle MySQL
| (component: Connector/Python).  Supported versions that are affected
| are 9.0.0 and prior. Difficult to exploit vulnerability allows low
| privileged attacker with network access via multiple protocols to
| compromise MySQL Connectors.  Successful attacks of this
| vulnerability can result in takeover of MySQL Connectors. CVSS 3.1
| Base Score 7.5 (Confidentiality, Integrity and Availability
| impacts).  CVSS Vector:
| (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2024-21272
    https://www.cve.org/CVERecord?id=CVE-2024-21272

Please adjust the affected versions in the BTS as needed.

--- End Message ---
--- Begin Message ---
Source: mysql-connector-python
Source-Version: 9.1.0-1
Done: Daniel Leidert <[email protected]>

We believe that the bug you reported is fixed in the latest version of
mysql-connector-python, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Daniel Leidert <[email protected]> (supplier of updated 
mysql-connector-python package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sun, 27 Oct 2024 21:02:57 +0100
Source: mysql-connector-python
Architecture: source
Version: 9.1.0-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Python Team <[email protected]>,
Changed-By: Daniel Leidert <[email protected]>
Closes: 1085297
Changes:
 mysql-connector-python (9.1.0-1) unstable; urgency=medium
 .
   * Team upload.
   * New upstream release.
     - Fixes CVE-2024-21272 (closes: #1085297).
Checksums-Sha1:
 5b116822adc32cfdcf77311f7f3a4eac093c60f7 2177 
mysql-connector-python_9.1.0-1.dsc
 600c1e5f4c8336a6528ee52765140b0d2ac1f6bc 16199496 
mysql-connector-python_9.1.0.orig.tar.gz
 89595322b94101adae51e9e98f0a9459f17d19da 5756 
mysql-connector-python_9.1.0-1.debian.tar.xz
 510c649d8f0e1a33305e02026cd0396555ca7dae 8863 
mysql-connector-python_9.1.0-1_amd64.buildinfo
Checksums-Sha256:
 a370a3625bcdce676d286d613a7698ec3e0813281a0e03480b66205e7ffce04f 2177 
mysql-connector-python_9.1.0-1.dsc
 6db01373167c39a89dc7bc8d1b47907a60c3fcd52dbba1e0d1ec0d4a788c1bec 16199496 
mysql-connector-python_9.1.0.orig.tar.gz
 02f8c0b1c0a29fddb7c2e836a7a5c6fa6fede877f76501aa3a7756bb4f1bb73f 5756 
mysql-connector-python_9.1.0-1.debian.tar.xz
 d42ab9599418b517cb59263c4ff4045affa624368d899ecddd0c024cfddb1815 8863 
mysql-connector-python_9.1.0-1_amd64.buildinfo
Files:
 9b64357abbc6b3ff5436e350592a363d 2177 python optional 
mysql-connector-python_9.1.0-1.dsc
 eac77c9e7f705e501c1fbdbc5a66a835 16199496 python optional 
mysql-connector-python_9.1.0.orig.tar.gz
 274480e14ba3d5b5e66f839ccb5ee5de 5756 python optional 
mysql-connector-python_9.1.0-1.debian.tar.xz
 0ebf510cc223161fc3433c27529b6f9b 8863 python optional 
mysql-connector-python_9.1.0-1_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEvu1N7VVEpMA+KD3HS80FZ8KW0F0FAmcenbkACgkQS80FZ8KW
0F1Ytg/+OBeLuBVwgPVLzxEdSdxyBJyJ+uSiaH/ChUyOlKo0Vn8yIACdlD+wNOCa
K3K+EFbNlkFQyBzOnulz/d4HXiTHZhgrxNeXwCoIkHAaairuG3AvUHH6fiAy6NfW
wf8G3wtYlS0kGn6oZhQozAg3tial52tzWn7jRTT5kryx6SYkKDteWYW+9SzSr5sl
3+jlVkFHQIPTFivq2yzFZ6v3PRTFlXw1jL9KejS/HW7vw5k+DkxprydsjSrve+/q
qcLhjMNnD/5mswxPlTxEUWBJ5PEQMhsQ9Br94hoR0DMlOV+hM1lU3km6BiTg8rnL
tGVTnATBPzmrdl+dIDQdVjF5TN0QE8pb5MaO2GA5ppSbbfTwES/IKgf4ILl5ZfGh
cs0yQMI200u8CL7H+BAuB7CfJTse9AgIJeTn98JWtE0OGvUtsfx9N4hdIpY1qvNp
fubFOJmc1Fa/lkMRmCodOHP/YDk44AYLwwPeRt6lUfmrp9LCc189MBh6XwFtDf/8
6UD928ErOb+6LDC708+/36CghcJ1eldPiCUt2X9UTx3SJ9fqAthW/GLajktrtb+A
oUIFxXhh5WOxDQHiQtnTmpGP2XrHDUnzWxFmj5/4LPqmufXMSss6oxCna3nLzgpp
b4/QsUK9sv1Wvl4ckuFSCjXD1uM5oGuMM6WGRdR0Qafk/ZesOfg=
=JIE5
-----END PGP SIGNATURE-----

Attachment: pgpIBZWKcbyk8.pgp
Description: PGP signature


--- End Message ---

Reply via email to