[Bug 1313187] Re: USN-2170-1: MySQL vulnerabilities also applies to MariaDB

2014-05-06 Thread Marc Deslauriers
** Changed in: mariadb-5.5 (Ubuntu Utopic) Status: In Progress => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1313187 Title: USN-2170-1: MySQL vulnerabilities also applies to M

[Bug 1313187] Re: USN-2170-1: MySQL vulnerabilities also applies to MariaDB

2014-05-05 Thread Seth Arnold
Thanks Otto -- I'm sorry I didn't make clear that I didn't need the patch header fixes for this update. Thanks for fixing them for the future, though, it'll be one fewer automated nag to ignore. Thanks! -- You received this bug notification because you are a member of Ubuntu Bugs, which is subsc

[Bug 1313187] Re: USN-2170-1: MySQL vulnerabilities also applies to MariaDB

2014-05-05 Thread Launchpad Bug Tracker
** Branch linked: lp:~ubuntu-branches/ubuntu/trusty/mariadb-5.5/trusty- security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1313187 Title: USN-2170-1: MySQL vulnerabilities also applies to MariaD

[Bug 1313187] Re: USN-2170-1: MySQL vulnerabilities also applies to MariaDB

2014-05-05 Thread Launchpad Bug Tracker
This bug was fixed in the package mariadb-5.5 - 5.5.37-0ubuntu0.14.04.1 --- mariadb-5.5 (5.5.37-0ubuntu0.14.04.1) trusty-security; urgency=medium * SECURITY UPDATE: Update to 5.5.37 to fix security issues (LP: #1313187) - http://www.oracle.com/technetwork/topics/security/cpuapr2

[Bug 1313187] Re: USN-2170-1: MySQL vulnerabilities also applies to MariaDB

2014-05-02 Thread Otto Kekäläinen
Added additional patch that makes the same change as in https://github.com/ottok/mariadb-5.5/commit/d0ba739a0 to reformat diff headers as requested. ** Patch added: "dpatch-to-quilt-format.diff" https://bugs.launchpad.net/ubuntu/+source/mariadb-5.5/+bug/1313187/+attachment/4103841/+files/dpatc

[Bug 1313187] Re: USN-2170-1: MySQL vulnerabilities also applies to MariaDB

2014-05-02 Thread Seth Arnold
Otto, thanks for this work. Thanks for filing the bug upstream to ask for signed tarballs and thanks for providing this update in near-perfect form. Our 'umt check' sanity checking tool complained about some missing patch tags: Patch tagging: 44_scripts__mysql_config__libs.diff

[Bug 1313187] Re: USN-2170-1: MySQL vulnerabilities also applies to MariaDB

2014-05-02 Thread Ubuntu Foundations Team Bug Bot
The attachment "mariadb-5.5_5.5.36-1_5.5.37-0ubuntu0.14.04.1-debian- dirs.diff" seems to be a debdiff. The ubuntu-sponsors team has been subscribed to the bug report so that they can review and hopefully sponsor the debdiff. If the attachment isn't a patch, please remove the "patch" flag from the

[Bug 1313187] Re: USN-2170-1: MySQL vulnerabilities also applies to MariaDB

2014-05-02 Thread Otto Kekäläinen
I now used the process outlined by Seth above to produce yet another Ubuntu security backport of 5.5.37. Instead of attaching the 21 MB debdiff file, I have now attached a diff that only has the debian/* contents. Steps for you to apply this patch: - apt-get source mariadb-server - on Trusty will

[Bug 1313187] Re: USN-2170-1: MySQL vulnerabilities also applies to MariaDB

2014-04-30 Thread Seth Arnold
Hello Otto, thanks for taking on this work. The Launchpad branches may be a convenient mechanism for managing packaging in the devel branch but it is not an ideal fit for security updates. I suspect that you can make it work, but working with the raw packaging pieces alone may be easier. When we

[Bug 1313187] Re: USN-2170-1: MySQL vulnerabilities also applies to MariaDB

2014-04-28 Thread Otto Kekäläinen
I now branched https://code.launchpad.net/~ubuntu- branches/ubuntu/trusty/mariadb-5.5/trusty and pushed at https://code.launchpad.net/~otto/maria/5.5.37-0ubuntu0.14.04.1 and built in my own PPA using recipe at https://code.launchpad.net/~otto/+recipe/mariadb-5.5-security-update. Build was OK and a

[Bug 1313187] Re: USN-2170-1: MySQL vulnerabilities also applies to MariaDB

2014-04-26 Thread Dimitri John Ledkov
Well my comment above is not correct, given the intentions of ongoing security updates and/or eventual MRE. in this case, he needs to get a couple of updates sponsored by the security team, and then can apply for a MRE so he needs to file a bug, propose some updated packages that only touch th

[Bug 1313187] Re: USN-2170-1: MySQL vulnerabilities also applies to MariaDB

2014-04-26 Thread Dimitri John Ledkov
A fake-sync from utopic-release pocket into trusty-security might be appropriate - similar to DSA fakesyncs. ** Also affects: mariadb-5.5 (Ubuntu Trusty) Importance: Undecided Status: New ** Also affects: mariadb-5.5 (Ubuntu Utopic) Importance: Undecided Status: New ** Change