Bug 21101 - mariadb 10.1.24
Summary: mariadb 10.1.24
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: AL13N
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2017-06-17 03:13 CEST by David Walser
Modified: 2017-07-06 22:22 CEST (History)
3 users (show)

See Also:
Source RPM: mariadb-10.1.23-1.mga6.src.rpm
CVE:
Status comment: Issue in downstream script needs to be fixed manually


Attachments

Description David Walser 2017-06-17 03:13:47 CEST
Upstream has released MariaDB 10.1.24 on May 31:
https://mariadb.com/kb/en/mariadb/mariadb-10124-release-notes/

Fedora has issued an advisory for this today (June 16):
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/MDVYS43SNVTIM4TF72GOUFHSEEXCOV6N/

Their advisory claims it fixes some CVEs, though the MariaDB release notes don't list those (yet?).  Perhaps they were fixed in one of the previously releases, as Fedora is updating from 10.1.21:
CVE-2017-3313 CVE-2017-3308 CVE-2017-3309 CVE-2017-3453 CVE-2017-3456 CVE-2017-3464

However, their git log also mentions CVE-2017-3265, fixed in a downstream script, mariadb-prepare-db-dir.  We have a mysqld-prepare-db-dir that isn't exactly the same, but is very similar and probably has a common ancestor.  Furthermore, it is probably affected by whatever the security issue was and needs to be updated similarly.
Comment 1 David Walser 2017-06-17 03:14:42 CEST
Update to 10.1.24 in Cauldron SVN, but files list probably still needs to be updated, and the mysqld-prepare-db-dir still needs to be fixed.
Comment 2 Marja Van Waes 2017-06-19 15:21:00 CEST
Assigning to the registered maintainer, but CC'ing all packagers collectively, in case the maintainer is unavailable.

Assignee: bugsquad => alien
CC: (none) => marja11, pkg-bugs

David Walser 2017-06-24 18:59:06 CEST

Status comment: (none) => Issue in downstream script needs to be fixed manually

Comment 3 Thomas Backlund 2017-07-06 21:13:26 CEST
Fixed for Cauldron in mariadb-10.1.24-1.mga6 currently building

Version: Cauldron => 5
CC: (none) => tmb

Comment 4 David Walser 2017-07-06 22:22:07 CEST
Fixed in mariadb-10.1.24-1.mga6.  Thanks Thomas!

Status: NEW => RESOLVED
Resolution: (none) => FIXED
Version: 5 => Cauldron


Note You need to log in before you can comment on or make changes to this bug.