Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 661500 - <dev-db/mariadb-{10.0.35-r2,10.1.34}: Multiple vulnerabilities
Summary: <dev-db/mariadb-{10.0.35-r2,10.1.34}: Multiple vulnerabilities
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B2 [glsa+ cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2018-07-18 12:53 UTC by Brian Evans (RETIRED)
Modified: 2019-08-18 02:29 UTC (History)
2 users (show)

See Also:
Package list:
dev-db/mariadb-10.0.35-r2 dev-db/mariadb-10.1.34
Runtime testing required: ---
stable-bot: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Brian Evans (RETIRED) gentoo-dev 2018-07-18 12:53:22 UTC
List of Fixed CVEs in MariaDB versions

CVE-2018-2819: MariaDB 5.5.60, MariaDB 10.2.15, MariaDB 10.1.33, MariaDB 10.0.35
CVE-2018-2817: MariaDB 5.5.60, MariaDB 10.2.15, MariaDB 10.1.33, MariaDB 10.0.35
CVE-2018-2813: MariaDB 5.5.60, MariaDB 10.2.15, MariaDB 10.1.33, MariaDB 10.0.35
CVE-2018-2810: MariaDB 10.2.15
CVE-2018-2787: MariaDB 10.2.15, MariaDB 10.1.33, MariaDB 10.0.35
CVE-2018-2786: MariaDB 10.2.15
CVE-2018-2784: MariaDB 10.2.15, MariaDB 10.1.33, MariaDB 10.0.35
CVE-2018-2782: MariaDB 10.2.15, MariaDB 10.1.33, MariaDB 10.0.35
CVE-2018-2781: MariaDB 5.5.60, MariaDB 10.2.15, MariaDB 10.1.33, MariaDB 10.0.35
CVE-2018-2777: MariaDB 10.2.15
CVE-2018-2771: MariaDB 5.5.60, MariaDB 10.2.15, MariaDB 10.1.33, MariaDB 10.0.35
CVE-2018-2766: MariaDB 10.2.15, MariaDB 10.1.33, MariaDB 10.0.35
CVE-2018-2761: MariaDB 5.5.60, MariaDB 10.2.15, MariaDB 10.1.33, MariaDB 10.0.35
CVE-2018-2759: MariaDB 10.2.15
CVE-2018-2755: MariaDB 5.5.60, MariaDB 10.2.15, MariaDB 10.1.33, MariaDB 10.0.35
Comment 1 Brian Evans (RETIRED) gentoo-dev 2018-07-18 12:58:42 UTC
@ Arches, please test and mark stable.
The test suite should pass following the official instructions.
Local timeouts may be expected on resource starved machines. (each test thread can spawn up to 4 server instances)

Target keywords:
=dev-db/mariadb-10.0.32 alpha amd64 arm ia64 ppc ppc64 x86
=dev-db/mariadb-10.1.26 alpha amd64 arm ia64 ppc ppc64 x86


# Official test instructions:
# USE='extraengine perl server' \
# FEATURES='test userpriv -usersandbox' \
# ebuild mariadb-10.0.32.ebuild \
# digest clean package

# Parallel testing is enabled, auto will try to detect number of cores
# You may set this by hand.
# The default maximum is 8 unless MTR_MAX_PARALLEL is increased
export MTR_PARALLEL="${MTR_PARALLEL:-auto}"
Comment 2 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2018-07-18 17:24:39 UTC
amd64 stable
Comment 3 Thomas Deutschmann (RETIRED) gentoo-dev 2018-07-20 22:43:00 UTC
=dev-db/mariadb-10.0.35-r2 x86 done,
dev-db/mariadb-10.1.34 not stabilized due to bug 661700
Comment 4 Larry the Git Cow gentoo-dev 2018-07-21 13:30:39 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=773e595d1a80b22e926ff28b11b3a2195fc2dc7f

commit 773e595d1a80b22e926ff28b11b3a2195fc2dc7f
Author:     Brian Evans <grknight@gentoo.org>
AuthorDate: 2018-07-21 13:29:47 +0000
Commit:     Brian Evans <grknight@gentoo.org>
CommitDate: 2018-07-21 13:30:28 +0000

    dev-db/mariadb: Mark stable on x86 after test failure fix
    
    Bug: https://bugs.gentoo.org/661500
    Package-Manager: Portage-2.3.42, Repoman-2.3.9

 dev-db/mariadb/mariadb-10.1.34.ebuild | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
Comment 5 Tobias Klausmann (RETIRED) gentoo-dev 2018-07-23 08:25:24 UTC
Stable on alpha.
Comment 6 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2018-07-30 23:58:05 UTC
arm stable
Comment 7 Sergei Trofimovich (RETIRED) gentoo-dev 2018-09-01 23:43:54 UTC
ia64 stable
Comment 8 Matt Turner gentoo-dev 2018-09-17 20:15:52 UTC
ppc/ppc64 stable. all arches stable
Comment 9 GLSAMaker/CVETool Bot gentoo-dev 2019-08-18 02:29:51 UTC
This issue was resolved and addressed in
 GLSA 201908-24 at https://security.gentoo.org/glsa/201908-24
by GLSA coordinator Aaron Bauman (b-man).