Bug#811428: [debian-mysql] Bug#811428: Bug#811428: mysql-5.5: Multiple security fixes from the January 2016 CPU

2016-01-28 Thread Salvatore Bonaccorso
Hi Robie, On Wed, Jan 27, 2016 at 06:32:24PM +, Robie Basak wrote: > On Wed, Jan 27, 2016 at 07:15:24PM +0100, Salvatore Bonaccorso wrote: > > Yes the dak mails for security-master are only sent to the security > > team. I can confirm that > > > > mysql-5.5_5.5.47-0+deb8u1_amd64.changes ACCEP

Bug#811428: [debian-mysql] Bug#811428: Bug#811428: mysql-5.5: Multiple security fixes from the January 2016 CPU

2016-01-27 Thread Salvatore Bonaccorso
Hi Robie, On Wed, Jan 27, 2016 at 05:10:58PM +, Robie Basak wrote: > Hi Salvatore, > > On Tue, Jan 26, 2016 at 08:17:30PM +0100, Salvatore Bonaccorso wrote: > > On Tue, Jan 26, 2016 at 06:36:06PM +, Robie Basak wrote: > > > Hi Salvatore, > > > > > > On Tue, Jan 26, 2016 at 01:19:26PM +01

Bug#811428: [debian-mysql] Bug#811428: Bug#811428: mysql-5.5: Multiple security fixes from the January 2016 CPU

2016-01-27 Thread Robie Basak
On Wed, Jan 27, 2016 at 07:15:24PM +0100, Salvatore Bonaccorso wrote: > Yes the dak mails for security-master are only sent to the security > team. I can confirm that > > mysql-5.5_5.5.47-0+deb8u1_amd64.changes ACCEPTED into stable->embargoed > > and > > mysql-5.5_5.5.47-0+deb7u1_amd64.changes A

Bug#811428: [debian-mysql] Bug#811428: Bug#811428: mysql-5.5: Multiple security fixes from the January 2016 CPU

2016-01-27 Thread Robie Basak
Hi Salvatore, On Tue, Jan 26, 2016 at 08:17:30PM +0100, Salvatore Bonaccorso wrote: > On Tue, Jan 26, 2016 at 06:36:06PM +, Robie Basak wrote: > > Hi Salvatore, > > > > On Tue, Jan 26, 2016 at 01:19:26PM +0100, Salvatore Bonaccorso wrote: > > > Thank you looks good to me. > > > > > > I haven

Bug#811428: [debian-mysql] Bug#811428: Bug#811428: mysql-5.5: Multiple security fixes from the January 2016 CPU

2016-01-26 Thread Salvatore Bonaccorso
Hi Robie, On Tue, Jan 26, 2016 at 06:36:06PM +, Robie Basak wrote: > Hi Salvatore, > > On Tue, Jan 26, 2016 at 01:19:26PM +0100, Salvatore Bonaccorso wrote: > > Thank you looks good to me. > > > > I haven't seen the same for jessie, but assuming it is basically the > > same and matching what

Bug#811428: [debian-mysql] Bug#811428: Bug#811428: mysql-5.5: Multiple security fixes from the January 2016 CPU

2016-01-26 Thread Robie Basak
Hi Salvatore, On Tue, Jan 26, 2016 at 01:19:26PM +0100, Salvatore Bonaccorso wrote: > Thank you looks good to me. > > I haven't seen the same for jessie, but assuming it is basically the > same and matching what you showed me initially from git, let's go > ahead with an upload. FYI, we're still

Bug#811428: [debian-mysql] Bug#811428: Bug#811428: mysql-5.5: Multiple security fixes from the January 2016 CPU

2016-01-26 Thread Salvatore Bonaccorso
Hi Lars, On Tue, Jan 26, 2016 at 01:11:45AM -0800, Lars Tangvald wrote: > Wheezy package has been built and tested > > At the moment it's just on my personal github at > https://github.com/ltangvald/mysql-5.5/tree/debian/wheezy, but we > should get it uploaded to Alioth soon. > Attaching the debd

Bug#811428: [debian-mysql] Bug#811428: mysql-5.5: Multiple security fixes from the January 2016 CPU

2016-01-25 Thread Lars Tangvald
Hi, I'll get it sent over shortly. -- Lars On 01/25/2016 08:57 AM, Salvatore Bonaccorso wrote: Hi Lars, On Fri, Jan 22, 2016 at 08:25:30AM -0800, Lars Tangvald wrote: Hi Salvatore, I'll get the wheezy-security package built and tested and send an update as soon as it's done. Great thanks!

Bug#811428: [debian-mysql] Bug#811428: mysql-5.5: Multiple security fixes from the January 2016 CPU

2016-01-25 Thread Salvatore Bonaccorso
Hi Lars, On Fri, Jan 22, 2016 at 08:25:30AM -0800, Lars Tangvald wrote: > Hi Salvatore, > > I'll get the wheezy-security package built and tested and send an update as > soon as it's done. Great thanks! In meanwhile could you please send the resulting debdiff for the jessie-security upload to

Bug#811428: [debian-mysql] Bug#811428: mysql-5.5: Multiple security fixes from the January 2016 CPU

2016-01-22 Thread Lars Tangvald
January 21, 2016 8:15:30 PM GMT +01:00 Amsterdam / Berlin / Bern / Rome / Stockholm / Vienna Subject: [debian-mysql] Bug#811428: mysql-5.5: Multiple security fixes from the January 2016 CPU Hi Robie, On Thu, Jan 21, 2016 at 09:46:13AM +, Robie Basak wrote: > Dear Security Team, > > Y

Bug#811428: mysql-5.5: Multiple security fixes from the January 2016 CPU

2016-01-21 Thread Salvatore Bonaccorso
Hi Robie, On Thu, Jan 21, 2016 at 09:46:13AM +, Robie Basak wrote: > Dear Security Team, > > You have asked us to be prompt with helping to prepare security updates > for you, and we have done so. We have kept the bug updated like you > asked us last time. The sources are tested and ready. We

Bug#811428: mysql-5.5: Multiple security fixes from the January 2016 CPU

2016-01-21 Thread Robie Basak
Dear Security Team, You have asked us to be prompt with helping to prepare security updates for you, and we have done so. We have kept the bug updated like you asked us last time. The sources are tested and ready. We notified the bug as requested, but haven't heard from you. Please let us know how

Bug#811428: mysql-5.5: Multiple security fixes from the January 2016 CPU

2016-01-20 Thread Lars Tangvald
http://anonscm.debian.org/cgit/pkg-mysql/mysql-5.5.git/ is updated. I'll send a notice to the security team. They may want us to do the upload, in which case we'll need someone who has the permissions to do so :) -- Lars Tangvald

Bug#811428: [debian-mysql] Bug#811428: Bug#811428: Bug#811428: mysql-5.5: Multiple security fixes from the January 2016 CPU

2016-01-20 Thread Lars Tangvald
On 01/20/2016 12:59 AM, Clint Byrum wrote: Is anyone working on the build/test/upload of the final binaries? I'm working with Robie to get the upload ready. Dep8 tests have passed on stable, and the changes made by the security team for previous releases should all be merged into my github tree

Bug#811428: [debian-mysql] Bug#811428: Bug#811428: mysql-5.5: Multiple security fixes from the January 2016 CPU

2016-01-19 Thread Lars Tangvald
The git tree is missing a copyright update made by the security team, which will need to be merged. -- Lars Tangvald On 01/19/2016 10:02 PM, Norvald H. Ryeng wrote: The Critical Patch Update is out: http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html The following vulne

Bug#811428: [debian-mysql] Bug#811428: Bug#811428: mysql-5.5: Multiple security fixes from the January 2016 CPU

2016-01-19 Thread Clint Byrum
Is anyone working on the build/test/upload of the final binaries? Excerpts from Norvald H. Ryeng's message of 2016-01-19 13:02:57 -0800: > The Critical Patch Update is out: > http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html > > The following vulnerabilities are fixed by

Bug#811428: [debian-mysql] Bug#811428: mysql-5.5: Multiple security fixes from the January 2016 CPU

2016-01-19 Thread Norvald H. Ryeng
The Critical Patch Update is out: http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html The following vulnerabilities are fixed by upgrading from MySQL 5.5.46 to 5.5.47: CVE-2016-0505 CVE-2016-0546 CVE-2016-0597 CVE-2016-0598 CVE-2016-0600 CVE-2016-0606 CVE-2016-0608 CVE

Bug#811428: [debian-mysql] Bug#811428: mysql-5.5: Multiple security fixes from the January 2016 CPU

2016-01-19 Thread Lars Tangvald
The updated changelog containing the CPU information can be found at https://github.com/ltangvald/mysql-5.5 The final commit is the only change from https://anonscm.debian.org/cgit/pkg-mysql/mysql-5.5.git -- Lars Tangvald

Bug#811428: mysql-5.5: Multiple security fixes from the January 2016 CPU

2016-01-18 Thread Norvald H. Ryeng
Source: mysql-5.5 Version: 5.5.46-0+deb8u1 Severity: grave Tags: security upstream fixed-upstream The Oracle Critical Patch Update for January 2016 will be released on Tuesday, January 19. According to the pre-release announcement [1], it will contain information about CVEs fixed in MySQL 5.5