| Summary: | mariadb new security issues fixed in 5.5.38 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | major | ||
| Priority: | Normal | CC: | alien, dpremy, mageia, oe, rverschelde, sysadmin-bugs |
| Version: | 4 | Keywords: | validated_update |
| Target Milestone: | --- | ||
| Hardware: | i586 | ||
| OS: | Linux | ||
| URL: | http://lwn.net/Vulnerabilities/605812/ | ||
| Whiteboard: | MGA3TOO has_procedure mga4-32-ok mga4-64-ok mga3-32-ok mga3-64-ok advisory | ||
| Source RPM: | mariadb-5.5.37-1.mga4.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2014-07-17 18:48:44 CEST
I guess we'll do a really generic advisory for now. It'd be nice if we can get some confirmation that those CVEs are relevant for this update. If so, we can include them. Advisory: ---------------------------------------- This update provides MariaDB 5.5.38, which fixes several bugs and potentially security issues. References: https://mariadb.com/kb/en/mariadb-5538-changelog/ http://www.mandriva.com/en/support/security/advisories/mbs1/MDVA-2014:007/ ---------------------------------------- Updated packages in core/updates_testing: ---------------------------------------- libmariadb-devel-5.5.38-1.mga3 libmariadb-embedded-devel-5.5.38-1.mga3 libmariadb-embedded18-5.5.38-1.mga3 libmariadb18-5.5.38-1.mga3 mariadb-5.5.38-1.mga3 mariadb-bench-5.5.38-1.mga3 mariadb-client-5.5.38-1.mga3 mariadb-common-5.5.38-1.mga3 mariadb-common-core-5.5.38-1.mga3 mariadb-core-5.5.38-1.mga3 mariadb-extra-5.5.38-1.mga3 mariadb-feedback-5.5.38-1.mga3 mariadb-obsolete-5.5.38-1.mga3 mysql-MariaDB-5.5.38-1.mga3 libmariadb-devel-5.5.38-1.mga4 libmariadb-embedded-devel-5.5.38-1.mga4 libmariadb-embedded18-5.5.38-1.mga4 libmariadb18-5.5.38-1.mga4 mariadb-5.5.38-1.mga4 mariadb-bench-5.5.38-1.mga4 mariadb-client-5.5.38-1.mga4 mariadb-common-5.5.38-1.mga4 mariadb-common-core-5.5.38-1.mga4 mariadb-core-5.5.38-1.mga4 mariadb-extra-5.5.38-1.mga4 mariadb-feedback-5.5.38-1.mga4 mariadb-obsolete-5.5.38-1.mga4 mysql-MariaDB-5.5.38-1.mga4 from SRPMS: mariadb-5.5.38-1.mga3.src.rpm mariadb-5.5.38-1.mga4.src.rpm CC:
(none) =>
alien, oe it seems the primary security person from mariadb is on leave atm, but since the changelog lists a mysql-5.5.38 merge, i'm assuming yes. Thanks AL13N! Updated advisory. Advisory: ======================== Updated mariadb packages fix security vulnerabilities: This update provides MariaDB 5.5.38, which fixes several security issues and other bugs. References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2494 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4207 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4258 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4260 https://mariadb.com/kb/en/mariadb-5538-changelog/ http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html http://www.ubuntu.com/usn/usn-2291-1/ Testing complete mga4 64 using wordpress and phpmyadmin with the updates installed Whiteboard:
MGA3TOO =>
MGA3TOO has_procedure mga4-64-ok Testing complete mga4 32 with phpmyadmin & owncloud configured with mysql DB
claire robinson
2014-07-18 16:59:50 CEST
Whiteboard:
MGA3TOO has_procedure mga4-64-ok =>
MGA3TOO has_procedure mga4-32-ok mga4-64-ok Also tested with phpmyadmin and mediawiki on both mga4 32 and 64. No issue found. CC:
(none) =>
dpremy tested with phpmyadmin, on commandline and upgrade and install a new wordpress log on mga3 32bit. Everything is working fine. Whiteboard:
MGA3TOO has_procedure mga4-32-ok mga4-64-ok =>
MGA3TOO has_procedure mga4-32-ok mga4-64-ok mga3-32-ok performed same tests as above on mga3 64bit as well and no errors detected. Please upload the advisory and then the update can be pushed to updates. Whiteboard:
MGA3TOO has_procedure mga4-32-ok mga4-64-ok mga3-32-ok =>
MGA3TOO has_procedure mga4-32-ok mga4-64-ok mga3-32-ok mga3-64-ok Validating now so it doesn't get missed. The advisory still needs to be uploaded. Sysadmins, please push this to updates for Mageia 3 and Mageia 4. Keywords:
(none) =>
validated_update Advisory uploaded. CC:
(none) =>
remi Update pushed. http://advisories.mageia.org/MGASA-2014-0299.html Status:
NEW =>
RESOLVED LWN reference for CVE-2015-0391, fixed in 5.5.38 (CVE recently assigned): http://lwn.net/Vulnerabilities/631836/ |