|
|
|
|
Changelog for mysql-connector-java-5.1.47-lp152.2.3.1.noarch.rpm :
* Tue Jul 27 2021 Pedro Monreal - Security fix: [bsc#1173600, CVE-2020-2875, CVE-2020-2933, CVE-2020-2934] * CVE-2020-2875: Unauthenticated attacker with network access via multiple protocols can compromise MySQL Connectors. Can result in unauthorized update, insert or delete access to some of MySQL Connectors accessible data as well as unauthorized read access to a subset of MySQL Connectors accessible data. * CVE-2020-2934: Can result in unauthorized update, insert or delete access to some of MySQL Connectors accessible data as well as unauthorized read access to a subset of MySQL Connectors accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Connectors. * CVE-2020-2933: Allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Connectors. * https://www.oracle.com/security-alerts/cpuapr2020verbose.html#MSQL * Add mysql-connector-java-CVE-2020-2875_CVE-2020-2933_CVE-2020-2934.patch * Tue Oct 01 2019 Fridrich Strba - Build against the new compatibility packages log4j12/log4j12-mini- Clean the spec file by spec-cleaner * Mon Nov 05 2018 Pedro Monreal Gonzalez - Updated to 5.1.47 - Bug#28449601, MASTER : UNITTEST FOR BUG#22305979 (TESTBUG22305979) STILL FAILS ON QA SETUP. - Bug#81063 (23098159), w/ rewriteBatchedStatements, when 2 tables involved, the rewriting not correct. - Bug#84813 (25501750), rewriteBatchedStatements fails in INSERT. - Fix for Bug#81196 (23227334), CONNECTOR/J NOT FOLLOWING DATABASE CHARACTER SET. - Bug#72609 (18749544), SETDATE() NOT USING A PROLEPTIC GREGORIAN CALENDAR. - Bug#87534 (26730196), UNION ALL query fails when useServerPrepStmts=true on database connection. Test case only. Base bug fixed in MySQL 5.7.22. - Bug#89948 (27658489), Batched statements are not committed for useLocalTransactionState=true. - BUG#80532 (22847443), ENCODING OF RESULTSET.UPDATEROW IS BROKEN FOR NON ASCII CHARCTERS. - BUG#22305979, WRONG RECORD UPDATED IF SENDFRACTIONALSECONDS=FALSE AND SMT IS SCROLLABLE. - BUG#90024 (27677574), SOME TESTS FAILED AGAINST MYSQL 8.0.5 BECAUSE OF DEPRECATED FEATURES REMOVAL.- Updated to 5.1.46 - WL#11629, Change caching_sha2_password padding. - Bug#86741 (26314325), Multi-Host connection with autocommit=0 getAutoCommit maybe wrong. - Bug#27231383, PROVIDE MAVEN-FRIENDLY COMMERCIAL PACKAGES WITHOUT \"-BIN\". - Bug#26819691, SETTING PACKETDEBUGBUFFERSIZE=0 RESULTS IN CONNECTION FAILURE. - WL#11200, Add caching_sha2_password support. - Bug#88227 (27029657), Connector/J 5.1.44 cannot be used against MySQL 5.7.20 without warnings. - Bug#27374581, CONNECTION FAILS WHEN GPL SERVER STARTED WITH TLS-VERSION=TLSV1.2. - Bug#79612 (22362474), CONNECTION ATTRIBUTES LOST WHEN CONNECTING WITHOUT DEFAULT DATABASE.- Updated to 5.1.45 - Bug#27131768, NULL POINTER EXCEPTION IN CONNECTION. - Bug#88232 (27047676), c/J does not rollback transaction when autoReconnect=true. - Bug#88242 (27040063), autoReconnect and socketTimeout JDBC option makes wrong order of client packet. - Bug#88021 (26939943), High GC pressure when driver configured with serversideprepared statements. - Bug#26724085, CHARSET MAPPING TO BE UPDATED FOR MYSQL 8.0.3. - Bug#26794652, TEST FAILING DUE TO BINARY LOGGING ENABLED BY DEFAULT IN MYSQL 8.0.3. - Bug#26794602, TESTS FAILING DUE TO CHANGE IN INFORMATION_SCHEMA.INNODB_SYS_ * NAMING. - Bug#87704 (26771560), THE STREAM GETS THE RESULT SET ?THE DRIVER SIDE GET WRONG ABOUT GETLONG().- Updated to 5.1.44 - Bug#87429 (26633984), repeated close of ServerPreparedStatement causes memory leak. - Bug#87379 (26646676), Perform actual TLS capabilities check when restricting TLSv1.2. - Bug#85601 (25777822), Unit notation is missing in the description of the property involved in the time. - Bug#87153 (26501245), INCORRECT RESULT OF DBMD.GETVERSIONCOLUMNS() AGAINST MYSQL 8.0.2+. - Bug#26440544, CONNECTOR/J SHOULD NOT USE TX_{READ_ONLY,ISOLATION} WHICH IS PLANNED FOR REMOVAL.- Rebased patch mysql-connector-java-jdbc-4.1.patch * Fri Oct 06 2017 fstrbaAATTsuse.com- Fix build with jdk9- Added patch: * mysql-connector-java-sourcetarget.patch + Don\'t hardcode java source and target levels; specify them on command-line. * Fri Sep 29 2017 fstrbaAATTsuse.com- Don\'t condition the maven defines on release version, but on _maven_repository being defined * Sun Sep 10 2017 fstrbaAATTsuse.com- Require for building java-devel = 1.8.0, since this package needs a javac compiler able to build with source and target level 1.5 * Mon Aug 21 2017 pmonrealgonzalezAATTsuse.com- Update to version 5.1.43 * Fixed problems connecting to MYSQL 8.0.3. * Deprecating COM_SHUTDOWN * GETDATE(),GETTIME() AND GETTIMESTAMP() called with NULL calendar returs NPE * C/J 5.1 GIS tests are failing with MYSQL 8.0.1C/J 5.1 GIS * Updated time zone mappings with latest TZ databases * For a full list of fixed issues see CHANGES or: http://dev.mysql.com/doc/relnotes/connector-j/en/news-5-1.html * Fri May 19 2017 dziolkowskiAATTsuse.com- New build dependency: javapackages-local- cleaned spec using spec-cleaner * Thu May 18 2017 tchvatalAATTsuse.com- Hardcode requirement for java 1.8 or newer to build * Thu May 18 2017 tchvatalAATTsuse.com- Drop patch use-classpath-in-tests.patch- Add patch disabling testsuite: * disable-testsuite.patch- Drop patch extra-libs-build.patch: * Rather use the thing to propagate some wrongly found libs- Drop patch no-jdk5-requirement.patch: * Simply override the value in ant command- Add patch hibernate-check.patch to remove hibernate check- Add patch compile-jdk7.patch to compile with old JDK versions * Thu May 18 2017 tchvatalAATTsuse.com- Version update to 5.1.42 bsc#1035210 bsc#1035697 bsc#1035211: * CVE-2017-3589 CVE-2017-3523 CVE-2017-3586 * http://dev.mysql.com/doc/relnotes/connector-j/en/news-5-1.html- Remove upstreamed mysql-connector-java-5.1.35-CVE-2017-3523.patch- Refresh patch extra-libs-build.patch- Drop obsolete patch jdk6-check-use-jdk7.patch- Refresh patch no-jdk5-requirement.patch- Attempt to refresh mysql-connector-java-jdbc-4.1.patch * Partialy merged by upstream, many conflicts- Add patch to relax compiler check: * javac-check.patch * Tue May 02 2017 pmonrealgonzalezAATTsuse.com- Fix for CVE-2017-3523 (bsc#1035697) * Unexpected automatic deserialisation of Java objects * Affected software: MySQL Connector/J * Remote Code Execution Vulnerability- Added patch: mysql-connector-java-5.1.35-CVE-2017-3523.patch * Thu Jun 11 2015 tchvatalAATTsuse.com- Fix the patches to allow jdbc3 build and reenable it: * mysql-connector-java-jdbc-4.1.patch * no-jdk5-requirement.patch * Tue Apr 21 2015 tchvatalAATTsuse.com- Update to 5.1.35 (see CHANGES for full list of issues) bnc#927981 CVE-2015-2575: * http://dev.mysql.com/doc/relnotes/connector-j/en/news-5-1.html- Remove not applicable patch: * mysql-connector-java-7-jdbc-4.1.patch- Do not explicitely check for jdk6 but be happy with 7 and 8: * jdk6-check-use-jdk7.patch- Do not require hibernate4 to actually build: * extra-libs-build.patch- Do not build jdk5 depending jdbc3: * no-jdk5-requirement.patch- Add and rebase jdbc4.1 patch: * mysql-connector-java-jdbc-4.1.patch- Add new patch to build tests: * use-classpath-in-tests.patch * Wed Mar 18 2015 tchvatalAATTsuse.com- Fix build with new javapackages-tools
|
|
|