Bug#775882: [debian-mysql] Bug#775882: Bug#775882: mariadb-10.0: affected by CVEs of the Oracle Patch Update for January 2015?

2015-02-02 Thread Otto Kekäläinen
After a few rounds of uploads to experimental builds on all platforms now pass as usual and I've today uploaded to unstable 10.0.16-1, but forgot to close this bug via the changelog, so the changelog is now manually attached here: mariadb-10.0 (10.0.16-1) unstable; urgency=low [ Julien Muchembl

Bug#775882: [debian-mysql] Bug#775882: mariadb-10.0: affected by CVEs of the Oracle Patch Update for January 2015?

2015-01-28 Thread Otto Kekäläinen
Status: The test suite failed. I found out that the cacert.pem that is part of the test suite expired today at 6 am UTC. I am working with devs to get this cert re-issued and test suite successful again. I did upload https://buildd.debian.org/status/package.php?p=mariadb-10.0&suite=experimental

Bug#775882: [debian-mysql] Bug#775882: mariadb-10.0: affected by CVEs of the Oracle Patch Update for January 2015?

2015-01-27 Thread Salvatore Bonaccorso
Hi Otto, On Tue, Jan 27, 2015 at 09:20:51PM +0200, Otto Kekäläinen wrote: > 2015-01-27 8:09 GMT+02:00 Salvatore Bonaccorso : > > Thanks for the update and checking with upstream regarding the two > > other CVEs. 10.0.16 seems now avaiable[1] (even though not yet > > announced on the webpage itself

Bug#775882: [debian-mysql] Bug#775882: mariadb-10.0: affected by CVEs of the Oracle Patch Update for January 2015?

2015-01-27 Thread Otto Kekäläinen
2015-01-27 8:09 GMT+02:00 Salvatore Bonaccorso : > Thanks for the update and checking with upstream regarding the two > other CVEs. 10.0.16 seems now avaiable[1] (even though not yet > announced on the webpage itself). > > [1] https://downloads.mariadb.com/files/MariaDB/mariadb-10.0.16/source 1

Bug#775882: [debian-mysql] Bug#775882: mariadb-10.0: affected by CVEs of the Oracle Patch Update for January 2015?

2015-01-27 Thread Salvatore Bonaccorso
Hi Otto, On Tue, Jan 27, 2015 at 10:01:09AM +0200, Otto Kekäläinen wrote: > Here is the reply from a MariaDB core developer: > > 2015-01-26 21:39 GMT+02:00 Sergei Golubchik : > > Hi, Otto! > > > > On Jan 26, Otto Kekäläinen wrote: > >> Hello Sergei! > >> > >> The page https://mariadb.com/kb/en/ma

Bug#775882: [debian-mysql] Bug#775882: mariadb-10.0: affected by CVEs of the Oracle Patch Update for January 2015?

2015-01-27 Thread Otto Kekäläinen
Here is the reply from a MariaDB core developer: 2015-01-26 21:39 GMT+02:00 Sergei Golubchik : > Hi, Otto! > > On Jan 26, Otto Kekäläinen wrote: >> Hello Sergei! >> >> The page https://mariadb.com/kb/en/mariadb/security/ does not mention >> the ones Salvatore asks about below: 0385 and 0409. Any i

Bug#775882: [debian-mysql] Bug#775882: mariadb-10.0: affected by CVEs of the Oracle Patch Update for January 2015?

2015-01-26 Thread Salvatore Bonaccorso
Hi Otto, On Mon, Jan 26, 2015 at 09:03:28PM +0200, Otto Kekäläinen wrote: > The page https://mariadb.com/kb/en/security/ has updated and includes > info about these latest CVEs. > > It seems most issues were fixed in 5.5.41/10.0.16. > One was for 5.5.39/10.0.13. > > 10.0.16 hasn't been yet relea

Bug#775882: [debian-mysql] Bug#775882: mariadb-10.0: affected by CVEs of the Oracle Patch Update for January 2015?

2015-01-26 Thread Otto Kekäläinen
The page https://mariadb.com/kb/en/security/ has updated and includes info about these latest CVEs. It seems most issues were fixed in 5.5.41/10.0.16. One was for 5.5.39/10.0.13. 10.0.16 hasn't been yet released, but I'll expect it is released soon and I will try to be as fast as possible in upda

Bug#775882: [debian-mysql] Bug#775882: mariadb-10.0: affected by CVEs of the Oracle Patch Update for January 2015?

2015-01-26 Thread Salvatore Bonaccorso
Control: tags -1 upstream fixed-upstream Control: retitle -1 mariadb-10.0: CVE-2015-0411 CVE-2015-0382 CVE-2015-0381 CVE-2015-0432 CVE-2014-6568 CVE-2015-0374 Hi Otto, On Fri, Jan 23, 2015 at 08:46:46AM +0200, Otto Kekäläinen wrote: > I started to search information about this 2 days ago, but so

Bug#775882: [debian-mysql] Bug#775882: mariadb-10.0: affected by CVEs of the Oracle Patch Update for January 2015?

2015-01-22 Thread Salvatore Bonaccorso
Hi Otto, On Fri, Jan 23, 2015 at 08:46:46AM +0200, Otto Kekäläinen wrote: > I started to search information about this 2 days ago, but so far I > haven't found any indication that these would affect MariaDB, though I > haven't got the definitive final reply from mariadb devs confirming so > either

Bug#775882: [debian-mysql] Bug#775882: mariadb-10.0: affected by CVEs of the Oracle Patch Update for January 2015?

2015-01-22 Thread Otto Kekäläinen
I started to search information about this 2 days ago, but so far I haven't found any indication that these would affect MariaDB, though I haven't got the definitive final reply from mariadb devs confirming so either. -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a s

Bug#775882: mariadb-10.0: affected by CVEs of the Oracle Patch Update for January 2015?

2015-01-20 Thread Salvatore Bonaccorso
Source: mariadb-10.0 Version: 10.0.15-3 Severity: grave Tags: security Hi MariaDB maintainers! As you might have seen there is a new Oracle Patch Update including updates for MySQL 5.5. I'm filling this bug to just have it double-checked as mariadb.com does not list yet new versions afaics: http