USN-2881-1: MySQL vulnerabilities also apply to MariaDB
Bug #1538315 reported by
Otto Kekäläinen
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
mariadb-10.0 (Ubuntu) |
Fix Released
|
Medium
|
Unassigned | ||
Vivid |
Fix Released
|
Medium
|
Steve Beattie | ||
Wily |
Fix Released
|
Medium
|
Steve Beattie |
Bug Description
The mentioned security notice also affect MariaDB and the latest release includes fixes.
For trusty I already did mariadb-5.5.47 on December 10th:
https:/
Nobody uploaded it despite that it is a point release with MRE granted. Can you
upload it now?
For wily and vivid I'll prepare mariadb-10.0 version 10.0.23 now and attach as patches to this bug report.
Xenial already got 10.0.23 automatically from Debian testing/sid.
information type: | Private Security → Public Security |
Changed in mariadb-10.0 (Ubuntu): | |
importance: | Undecided → Medium |
To post a comment you must log in.
Use uscan to get new upstream sources downloaded and signature verified automatically.
Remove the upstream provided debian/ directory and add the debian/* contents from the latest Ubuntu package.
Then apply the attached debdiff that updates the changelog and refreshes patches to match new upstream release.
Debdiff was created with command "git diff ubuntu/ 10.0.22- 0ubuntu0. 15.04.1. .HEAD debian/ > 10.0.22- 0ubuntu0. 15.04.1. .10.0.23- 0ubuntu0. 15.04.1. debdiff" in the official Debian packaging repository, branch ubuntu-15.04: http:// anonscm. debian. org/cgit/ pkg-mysql/ mariadb- 10.0.git/ log/?h= ubuntu- 15.04
As the MariaDB version in vivid and wily is identical, this same patch can basically be applied on both (just adjust the release name).
Please check the excellent Debian CVE trackers for details about which CVE applies to which package. Note in particular that MariaDB 10.0.23 has this fixed but it still goes unfixed in MySQL releases: https:/ /security- tracker. debian. org/tracker/ CVE-2016- 2047