Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 546308 - glsa 201504-05,201507-19 - please add MySQL/MariaDB 5.5 to unaffected versions
Summary: glsa 201504-05,201507-19 - please add MySQL/MariaDB 5.5 to unaffected versions
Status: RESOLVED WONTFIX
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: GLSA Errors (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Linux MySQL bugs team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2015-04-12 04:59 UTC by Tomáš Mózes
Modified: 2016-01-26 13:12 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Tomáš Mózes 2015-04-12 04:59:54 UTC
Glsa states that only MySQL 5.6 / MariaDB 10.0 are not vulnerable, however series 5.5 are also still supported and maintained.
Comment 1 Tobias Heinlein (RETIRED) gentoo-dev 2015-04-13 08:01:42 UTC
MySQL team, what's your take on this? 5.5 is package.mask'ed. Was this done by your choice or because upstream doesn't support it anymore?
Comment 2 Tomáš Mózes 2015-04-13 10:46:32 UTC
(In reply to Tobias Heinlein from comment #1)
> ... or because upstream doesn't support it anymore?

Both MySQL 5.5 and MariaDB 5.5 are still supported.
Comment 3 Brian Evans (RETIRED) gentoo-dev 2015-04-13 12:23:59 UTC
(In reply to Tobias Heinlein from comment #1)
> MySQL team, what's your take on this? 5.5 is package.mask'ed. Was this done
> by your choice or because upstream doesn't support it anymore?

The 5.5 series was not put in package.mask but the keywords were dropped to ~arch. This was done because 1) 5.5 was not converted to multilib 2) not to put extra stress on the arch teams when a better version was available.

It is true that the 5.5 series are still getting security updates.
Comment 4 Tomáš Mózes 2015-04-14 09:33:28 UTC
I'm fine with setting a current version of 5.5 series as unaffected in the GLSA, no need to stabilize 5.5.
Comment 5 Yury German Gentoo Infrastructure gentoo-dev 2015-04-19 15:37:59 UTC
> The 5.5 series was not put in package.mask but the keywords were dropped to
> ~arch. This was done because 1) 5.5 was not converted to multilib 2) not to
> put extra stress on the arch teams when a better version was available.
> 
> It is true that the 5.5 series are still getting security updates.

Does 5.5.43 contain the latest security fixes? Bug 546722?
Comment 6 Tomáš Mózes 2015-04-21 05:39:32 UTC
(In reply to Yury German from comment #5)
> Does 5.5.43 contain the latest security fixes? Bug 546722?

Checking the Oracle MySQL Risk Matrix it seems 5.5.43 is unaffected, the vulnerable versions are 5.5.42 and earlier.
Comment 7 Tomáš Mózes 2015-09-08 08:59:55 UTC
On a system with the latest 5.5.45 (not vulnerable) I get:

201504-05 [N] [remote  ] MySQL and MariaDB: Multiple vulnerabilities ( dev-db/mariadb  dev-db/mysql-5.5.45 )
201507-19 [N] [remote  ] MySQL: Multiple vulnerabilities ( dev-db/mysql-5.5.45 )