Bug 8917 - mariadb new security issues fixed in 5.5.29
Summary: mariadb new security issues fixed in 5.5.29
Status: RESOLVED DUPLICATE of bug 8921
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: i586 Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Mageia Bug Squad
QA Contact:
URL: https://kb.askmonty.org/en/mariadb-55...
Whiteboard: MGA2TOO
Keywords:
Depends on:
Blocks:
 
Reported: 2013-01-31 20:54 CET by David Walser
Modified: 2013-01-31 22:47 CET (History)
2 users (show)

See Also:
Source RPM: mariadb
CVE:
Status comment:


Attachments

Description David Walser 2013-01-31 20:54:55 CET
MariaDB 5.5.29 has been released:
https://kb.askmonty.org/en/mariadb-5529-release-notes/

In the announcement it lists some security fixes that we haven't yet released:
- CVE-2012-5627/MDEV-3915
- CVE-2012-5615/MDEV-3909
- a variant of CVE-2012-5611.  We fixed 5611 itself, but this may be different.
- fixes for DoS attacks
- other security fixes from MySQL 5.5.29 (not including 5612 which we fixed)
David Walser 2013-01-31 20:55:09 CET

CC: (none) => alien
Whiteboard: (none) => MGA2TOO

David Walser 2013-01-31 20:55:15 CET

CC: (none) => fundawang

Comment 1 AL13N 2013-01-31 21:00:39 CET
no.

we're in version freeze, and there's symbol versioning changes, which makes our versioning hacks fail, and since this could have effects for php-mysql, perl-DBD-mysql etc...

i'm not planning on updating (for now).

as always, i'm patching security and major bugfixes (in the process of doing it)

Status: NEW => RESOLVED
Resolution: (none) => WONTFIX

Comment 2 David Walser 2013-01-31 21:41:03 CET
That's not to say we have to upgrade to 5.5.29, but there are some additional security fixes we should backport then that we haven't yet.

Status: RESOLVED => REOPENED
Resolution: WONTFIX => (none)

Comment 3 AL13N 2013-01-31 22:04:26 CET
i've been working on it since day before yesterday... it's coming tonight
Comment 4 David Walser 2013-01-31 22:22:18 CET
OK, I hope you don't feel like anyone's rushing you.

We'd need the bug filed at some point anyway, that's why I filed it.
Comment 5 AL13N 2013-01-31 22:47:38 CET
np, it's just that i had already been preparing bugreports and fixes. i wanted it fixed yesterday, but RL intervened...

*** This bug has been marked as a duplicate of bug 8921 ***

Status: REOPENED => RESOLVED
Resolution: (none) => DUPLICATE


Note You need to log in before you can comment on or make changes to this bug.