Security issues (solved in Debian) - affecting mariadb-server in xenial and yakkety

Bug #1684274 reported by Andrei Coada
262
This bug affects 1 person
Affects Status Importance Assigned to Milestone
mariadb-10.0 (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

Security database references:
In Mitre's CVE dictionary: CVE-2017-3302, CVE-2017-3313.

The vulnerabilities are addressed by upgrading MariaDB to the new upstream version 10.0.30. Please see the MariaDB 10.0 Release Notes for further details:

https://mariadb.com/kb/en/mariadb/mariadb-10030-release-notes/

For the stable distribution (jessie), these problems have been fixed in version 10.0.30-0+deb8u1.

CVE References

information type: Public → Public Security
summary: - Security issues -> new upstream release (incl. Debian)
+ Security issues (solved in Debian) - affecting mariadb-server in xenial
+ and yakkety
Revision history for this message
Otto Kekäläinen (otto) wrote :

I plan to do a security update for Ubuntu like I've always done for the recent 3 years, but I was very busy in March/April and have not had time to do it yet... sorry

If the security issues were grave or if the package was in Ubuntu repository 'main' I would have acted immediately, but now I'll finish this once I've completed some other high priority issues elsewhere and have time for this.

Revision history for this message
Andrei Coada (raziel.kernel) wrote :

Thank you for your time and commitment on both projects (Debian and Ubuntu).

Changed in mariadb-10.0 (Ubuntu):
status: New → Confirmed
Revision history for this message
Otto Kekäläinen (otto) wrote :

I forgot about this original report and created a duplicate at https://bugs.launchpad.net/ubuntu/+source/mariadb-10.0/+bug/1698689

Anyway, MariaDB security uploads have been prepared for a security sponsor to upload (or to mentor me on how to do it if I can do it myself).

Revision history for this message
Faustin (fauust) wrote :
Changed in mariadb-10.0 (Ubuntu):
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.