USN-3357-1: partially applies to MariaDB too

Bug #1705944 reported by Otto Kekäläinen
258
This bug affects 1 person
Affects Status Importance Assigned to Milestone
mariadb-5.5 (Ubuntu)
Fix Released
Medium
Unassigned

Bug Description

https://usn.ubuntu.com/usn/usn-3357-1/

The security notice above also affect MariaDB and the latest release includes fixes.

I will produce a security release soon and attach more information to this bug report for:
 - mariadb-5.5 in Trusty

Currently we are not aware of any unfixed CVEs that apply for the 10.0 or 10.1 series.

CVE References

Otto Kekäläinen (otto)
information type: Public → Public Security
Revision history for this message
Otto Kekäläinen (otto) wrote :

The 5.5 series update for 14.04 is now available.

Please use git-buildpackage to fetch and build from the ubuntu-14.04 branch at http://anonscm.debian.org/cgit/pkg-mysql/mariadb-5.5.git/log/?h=ubuntu-14.04

The repository uses pristine-tar, so there is no need to separately download the sources. You can just check the signature/SHA1SUM directly from the git-buildpackage generated tarball.

Test builds and testsuite passed on all platforms at https://launchpad.net/~mysql-ubuntu/+archive/ubuntu/mariadb/+builds?build_text=&build_state=all

As a reminder, debdiffs can be browsed directly from the repo like this:
https://anonscm.debian.org/cgit/pkg-mysql/mariadb-5.5.git/diff/debian/?id=ubuntu/5.5.57-1ubuntu0.14.04.1&id2=ubuntu/5.5.56-1ubuntu0.14.04.1

Or in a local clone with 'git diff <tag1>..<tag2> debian/'

Security sponsor note these: https://wiki.ubuntu.com/SecurityTeam/PublicationNotes#Sponsoring_MariaDB_Security_Updates

Revision history for this message
Otto Kekäläinen (otto) wrote :

Ping security sponsors

Revision history for this message
Tyler Hicks (tyhicks) wrote :

Thanks Otto! This upload looks good to me and I've sponsored it into ppa:ubuntu-security-proposed/ppa. I should be able to release it later today.

Changed in mariadb-5.5 (Ubuntu):
status: New → Confirmed
importance: Undecided → Medium
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package mariadb-5.5 - 5.5.57-1ubuntu0.14.04.1

---------------
mariadb-5.5 (5.5.57-1ubuntu0.14.04.1) trusty-security; urgency=high

  * SECURITY UPDATE: New upstream release 5.5.57. Includes fixes made
    in release 5.5.55 for the following security vulnerabilities
    (LP: #1705944):
    - CVE-2017-3653
    - CVE-2017-3641
    - CVE-2017-3636
  * Update previous changelog entries to contain new CVE identifiers

 -- Otto Kekäläinen <email address hidden> Sun, 23 Jul 2017 23:38:03 +0300

Changed in mariadb-5.5 (Ubuntu):
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.