changelog 8.45 KB
Newer Older
1
2
3
4
5
6
7
8
9
10
11
mariadb-5.5 (5.5.50-1ubuntu0.14.04.1) trusty-security; urgency=low

  * SECURITY UPDATE: New upstream release 5.5.50 (LP: #1605493)
    - CVE-2016-5440
    - CVE-2016-3615
    - CVE-2016-3521
    - CVE-2016-3477
  * Update previous changelog entries to contain new CVE identifiers

 -- Otto Kekäläinen <otto@debian.org>  Fri, 22 Jul 2016 09:24:36 +0300

12
13
14
mariadb-5.5 (5.5.49-1ubuntu0.14.04.1) trusty-security; urgency=low

  * SECURITY UPDATE: New upstream release 5.5.49
15
16
    - CVE-2016-5444
    - CVE-2016-3452
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
    - CVE-2016-0647
    - CVE-2016-0648
    - CVE-2016-0666
    - CVE-2016-0643
  * After the release of 5.5.49 it was announced that 5.5.48 included fixes for
    the following security vulnerabilities:
    - CVE-2016-0640
    - CVE-2016-0644
    - CVE-2016-0646
    - CVE-2016-0649
    - CVE-2016-0650
    - CVE-2016-0641
  * Updated previous changelog entries to contain new CVE identifiers.

 -- Otto Kekäläinen <otto@debian.org>  Fri, 22 Apr 2016 22:13:38 +0300

33
mariadb-5.5 (5.5.47-1ubuntu0.14.04.1) trusty-security; urgency=low
34

35
36
37
38
39
40
41
42
43
44
45
  * SECURITY UPDATE: New upstream release 5.5.47
    - CVE-2016-0546
    - CVE-2016-0505
    - CVE-2016-0596
    - CVE-2016-0597
    - CVE-2016-0616
    - CVE-2016-0598
    - CVE-2016-0600
    - CVE-2016-0606
    - CVE-2016-0608
    - CVE-2016-0609
46
47
    - CVE-2016-0642
    - CVE-2016-0651
48
    - CVE-2016-2047
49
50
51
52
53
    - Adds the mariadb-slow.log into the logrotate file, as the file
      name mariadb-slow.log is the log name in the default config file.

 -- Otto Kekäläinen <otto@seravo.fi>  Thu, 10 Dec 2015 10:24:40 +0200

54
55
56
mariadb-5.5 (5.5.46-1ubuntu0.14.04.2) trusty-security; urgency=low

  * SECURITY UPDATE: Update to 5.5.46 to fix security issues (LP: #1512241):
57
58
    - CVE-2016-3471
    - CVE-2015-7744
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
    - CVE-2015-4913
    - CVE-2015-4870
    - CVE-2015-4861
    - CVE-2015-4858
    - CVE-2015-4836
    - CVE-2015-4830
    - CVE-2015-4826
    - CVE-2015-4815
    - CVE-2015-4807
    - CVE-2015-4802
    - CVE-2015-4792
  * Upstream release 5.5.45 fixes for the following security vulnerabilities:
    - CVE-2015-4816
    - CVE-2015-4819
    - CVE-2015-4879
  * Update new Oracle CVE identifiers to old MariaDB changelog entries
75
  * New patch: Extend date in test suite so that main.events_1 will pass
76
77
78

 -- Otto Kekäläinen <otto@seravo.fi>  Tue, 03 Nov 2015 11:41:30 +0200

79
mariadb-5.5 (5.5.44-1ubuntu0.14.04.1) trusty-security; urgency=low
Otto Kekäläinen's avatar
Otto Kekäläinen committed
80
81
82

  * SECURITY UPDATE: Update to 5.5.44 to fix security issues (LP: #1464895):
    - CVE-2015-3152
83
84
85
86
    - CVE-2015-2648
    - CVE-2015-2582
    - CVE-2015-4752
    - CVE-2015-2643
87
88
    - CVE-2015-4864
    - CVE-2015-2620
Otto Kekäläinen's avatar
Otto Kekäläinen committed
89
90
91
92
93
  * Upstream also includes lots of line ending changes (from CRLF -> LF)
  * Removed hotfix patch now included in upstream release (MDEV-8115)

 -- Otto Kekäläinen <otto@seravo.fi>  Sat, 13 Jun 2015 21:09:48 +0300

94
mariadb-5.5 (5.5.43-1ubuntu0.14.04.2) trusty-security; urgency=low
95
96
97
98
99
100

  * SECURITY UPDATE: Update to 5.5.43 to fix security issues (LP: #1451677):
    - CVE-2015-0501
    - CVE-2015-2571
    - CVE-2015-0505
    - CVE-2015-0499
101
    - CVE-2015-4757
102
  * Hotfix patch to fix the server crash caused by mysql_upgrade (MDEV-8115)
103
104
105

 -- Otto Kekäläinen <otto@seravo.fi>  Tue, 05 May 2015 09:17:31 +0300

106
mariadb-5.5 (5.5.41-1ubuntu0.14.04.1) trusty-security; urgency=medium
107
108
109
110
111
112
113
114

  * Critical backport from 10.0 (commit 439123d):
    Fix mariadb-server-5.5.postinst so that the flag removal will not emit
    an error code if there are no previous debian-*.flag files (LP: #1417917)

 -- Otto Kekäläinen <otto@seravo.fi>  Wed, 04 Feb 2015 11:28:16 +0200

mariadb-5.5 (5.5.41-0ubuntu0.14.04.2) trusty-security; urgency=medium
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133

  * SECURITY UPDATE: Update to 5.5.41 to fix security issues (LP: #1414755)
    - CVE-2015-0411
    - CVE-2015-0382
    - CVE-2015-0381
    - CVE-2015-0432
    - CVE-2014-6568
    - CVE-2015-0374
  * As approved by Seth Arnold, this security update also imports the latest
    mariadb-5.5 packaging from Debian which includes useful and low-risk
    fixes:
    - Updated Dutch translation by Frans Spiesschaert
    - Updated control file so that mariadb-client-5.5 breaks and replaces
      the package mariadb-server-5.5 to allow overwriting the innochecksum
      man page file which has changed location (LP: #1368124) as per
      doc https://www.debian.org/doc/debian-policy/ch-relationships.html#s7.6.1
    - Backported the fix of #770177 from 10.0 to 5.5 so that the migration
      question will not be asked repeatedly. (LP: #1392539)
   * Close delta between 14.10 and 14.04 in regards of packaging.
134
   * Backported new cacert.pem etc from 5.5 the replace the expired ones
135
136
137

 -- Otto Kekäläinen <otto@seravo.fi>  Tue, 27 Jan 2015 21:15:00 +0200

138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
mariadb-5.5 (5.5.40-0ubuntu0.14.04.1) trusty-security; urgency=medium

  * SECURITY UPDATE: Update to 5.5.40 to fix security issues (LP: #1391676)
    - CVE-2014-6507
    - CVE-2014-6491
    - CVE-2014-6500
    - CVE-2014-6469
    - CVE-2014-6555
    - CVE-2014-6559
    - CVE-2014-6494
    - CVE-2014-6496
    - CVE-2014-6464
  * Add bsdutils as mariadb-server dependency like upstream does in 5.5.40.

 -- Otto Kekäläinen <otto@seravo.fi>  Wed, 12 Oct 2014 01:04:24 +0200

mariadb-5.5 (5.5.39-0ubuntu0.14.04.1) trusty-security; urgency=medium

  * SECURITY UPDATE: Update to 5.5.39 to fix security issues (LP: #1363222)
    * 5.5.39
      - Fixes an error when handling MyISAM temporary files can be
        exploited to execute arbitrary code (Secunia Advisory SA60599)
    * 5.5.38
      - CVE-2014-2494
      - CVE-2014-4207
      - CVE-2014-4243
      - CVE-2014-4258
      - CVE-2014-4260
  * Import a few important packaging bug fixes available in Debian

 -- Otto Kekäläinen <otto@seravo.fi>  Fri, 29 Aug 2014 23:04:24 +0300

mariadb-5.5 (5.5.37-0ubuntu0.14.04.1) trusty-security; urgency=medium

  * SECURITY UPDATE: Update to 5.5.37 to fix security issues (LP: #1313187)
    - http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html
    - CVE-2014-0001
    - CVE-2014-0384
    - CVE-2014-2419
    - CVE-2014-2430
    - CVE-2014-2431
    - CVE-2014-2432
    - CVE-2014-2436
    - CVE-2014-2438
    - CVE-2014-2440

 -- Otto Kekäläinen <otto@seravo.fi>  Mon, 28 Apr 2014 09:55:22 +0300
185

James Page's avatar
James Page committed
186
mariadb-5.5 (5.5.36-1) unstable; urgency=low
187

188
  [ Otto Kekäläinen ]
James Page's avatar
James Page committed
189
190
  * New upstream release.
  * Updated Danish debconf translation (Closes: #739750).
191
  * d/control: Added explicit Conflicts/Replaces for mysql-5.6 packages
James Page's avatar
James Page committed
192
    (Closes: #739841).
193
194
  * d/control: Update for use of virtual-* packages for switching to/from
    MySQL alternatives.
195
196

  [ James Page ]
197
  * d/control: Drop Nicholas from Uploaders, MIA (Closes: #739360).
198
  * d/control: Add libjemalloc-dev to BD's.
199

200
 -- Otto Kekäläinen <otto@seravo.fi>  Sun, 02 Mar 2014 01:38:26 +0200
201

202
203
mariadb-5.5 (5.5.35-1) unstable; urgency=low

204
  [ Otto Kekäläinen ]
205
206
207
208
209
210
211
212
213
214
215
216
217
  * New upstream release, fixing the following security issues:
    - Buffer overflow in client/mysql.cc (Closes: #737597).
      - CVE-2014-0001
    - http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
      - CVE-2013-5891
      - CVE-2013-5908
      - CVE-2014-0386
      - CVE-2014-0393
      - CVE-2014-0401
      - CVE-2014-0402
      - CVE-2014-0412
      - CVE-2014-0420
      - CVE-2014-0437
218
219
220
221
222
  * Upstream https://mariadb.atlassian.net/browse/MDEV-4902
    fixes compatibility with Bison 3.0 (Closes: #733002)
  * Updated Russian debconf translation (Closes: #734426)
  * Updated Japanese debconf translation (Closes: #735284)
  * Updated French debconf translation (Closes: #736480)
223
  * Renamed SONAME properly (Closes: #732967)
224

225
 -- James Page <jamespage@debian.org>  Mon, 17 Feb 2014 16:51:52 +0000
226

227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
mariadb-5.5 (5.5.32-1) unstable; urgency=low

  [ Otto Kekäläinen ]
  * Initial package for Debian (Closes: #565308), based on upstream
    packaging:
    - mariadb-5.3 by Sergei Golubchik
    - mariadb-5.2 by Kristian Nielsen
    - mariadb-5.1 by Peter Lieverdink
  * Bring packaging up-to-date inline with mysql-5.5 packaging.
  * Refine control file and tidy lintian warnings
  * Rename libmysqlclient18 -> libmariadbclient18.
  * Add suitable Breaks/Replaces/Provides to support migration
    to/from mysql-server-5.5.
  * Plus multiple other updates based on feedback from Debian maintainers

  [ James Page ]
  * d/control,rules: Cherry picked fix from mysql-5.5 packaging to disable
    x86 assembler in taocrypt on i386 architectures, removing need for
    gcc-4.4 dependency.
  * d/control: Add myself to uploaders.
  * d/control: Update Vcs fields for new location on git.debian.org.

 -- Otto Kekäläinen <otto@seravo.fi>  Tue, 24 Sept 2013 15:09:51 +0300