changelog 11.1 KB
Newer Older
1
2
3
4
5
6
7
8
9
10
11
mariadb-5.5 (5.5.58-1ubuntu0.14.04.1) trusty-security; urgency=high

  * SECURITY UPDATE: New upstream release 5.5.58. Includes fixes for
    the following security vulnerabilities (LP: #1740608):
    - CVE-2017-10378, MDEV-13819
    - CVE-2017-10268
  * Update previous changelog entries to contain new CVE identifiers
  * Includes upstream MDEV-13819 server crash fix (LP: #1735876)

 -- Otto Kekäläinen <otto@debian.org>  Sat, 30 Dec 2017 17:55:52 +0200

12
13
14
15
16
mariadb-5.5 (5.5.57-1ubuntu0.14.04.1) trusty-security; urgency=high

  * SECURITY UPDATE: New upstream release 5.5.57. Includes fixes made
    in release 5.5.55 for the following security vulnerabilities
    (LP: #1705944):
17
18
    - CVE-2017-10384
    - CVE-2017-10379, MDEV-13187
19
20
21
22
23
24
    - CVE-2017-3653
    - CVE-2017-3641
    - CVE-2017-3636
  * Update previous changelog entries to contain new CVE identifiers

 -- Otto Kekäläinen <otto@debian.org>  Sun, 23 Jul 2017 23:38:03 +0300
25

26
mariadb-5.5 (5.5.56-1ubuntu0.14.04.1) trusty-security; urgency=high
27
28
29
30
31
32
33
34
35
36
37
38
39
  * SECURITY UPDATE: New upstream release 5.5.56. Includes fixes made
    in release 5.5.55 for the following security vulnerabilities
    (LP: #1698689):
    - CVE-2017-3464
    - CVE-2017-3456
    - CVE-2017-3453
    - CVE-2017-3313
    - CVE-2017-3309
    - CVE-2017-3308
    - CVE-2017-3302

 -- Otto Kekäläinen <otto@debian.org>  Sun, 18 Jun 2017 23:04:24 +0200

40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
mariadb-5.5 (5.5.54-1ubuntu0.14.04.1) trusty-security; urgency=high

  * SECURITY UPDATE: New upstream release 5.5.54. Includes fixes for the
    following security vulnerabilities (LP: #1657594):
    - CVE-2017-3318
    - CVE-2017-3317
    - CVE-2017-3312
    - CVE-2017-3291
    - CVE-2017-3265
    - CVE-2017-3258
    - CVE-2017-3244
    - CVE-2017-3243
    - CVE-2017-3238
    - CVE-2016-6664

 -- Otto Kekäläinen <otto@debian.org>  Thu, 19 Jan 2017 00:46:44 +0200

57
58
59
60
mariadb-5.5 (5.5.53-1ubuntu0.14.04.1) trusty-security; urgency=low

  * SECURITY UPDATE: New upstream release 5.5.53. Includes fixes for the
    following security vulnerabilities (LP: #1638125):
61
62
    - CVE-2017-3651
    - CVE-2017-3600
63
64
65
66
67
68
    - CVE-2016-7440
    - CVE-2016-5584
  * Update previous changelog entries to contain new CVE identifiers

 -- Otto Kekäläinen <otto@debian.org>  Mon, 31 Oct 2016 23:48:54 +0200

69
mariadb-5.5 (5.5.52-1ubuntu0.14.04.1) trusty-security; urgency=low
70

71
72
73
74
75
76
77
78
79
  * SECURITY UPDATE: New upstream release 5.5.52. Includes fixes for the
    following security vulnerabilities (LP: #1605493):
    - CVE-2016-8283
    - CVE-2016-6663
    - CVE-2016-5629
    - CVE-2016-5626
    - CVE-2016-5624
    - CVE-2016-5616
    - CVE-2016-3492
80
81
82
  * Previous release 5.5.51 included included fixes for
    the following security vulnerabilities:
    - CVE-2016-6662
83
    - CVE-2016-5612
84
85
  * Previous release 5.5.50 included included fixes for
    the following security vulnerabilities:
86
87
88
89
90
91
    - CVE-2016-5440
    - CVE-2016-3615
    - CVE-2016-3521
    - CVE-2016-3477
  * Update previous changelog entries to contain new CVE identifiers

92
 -- Otto Kekäläinen <otto@debian.org>  Wed, 14 Sep 2016 21:01:08 +0300
93

94
95
96
mariadb-5.5 (5.5.49-1ubuntu0.14.04.1) trusty-security; urgency=low

  * SECURITY UPDATE: New upstream release 5.5.49
97
98
    - CVE-2016-5444
    - CVE-2016-3452
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
    - CVE-2016-0647
    - CVE-2016-0648
    - CVE-2016-0666
    - CVE-2016-0643
  * After the release of 5.5.49 it was announced that 5.5.48 included fixes for
    the following security vulnerabilities:
    - CVE-2016-0640
    - CVE-2016-0644
    - CVE-2016-0646
    - CVE-2016-0649
    - CVE-2016-0650
    - CVE-2016-0641
  * Updated previous changelog entries to contain new CVE identifiers.

 -- Otto Kekäläinen <otto@debian.org>  Fri, 22 Apr 2016 22:13:38 +0300

115
mariadb-5.5 (5.5.47-1ubuntu0.14.04.1) trusty-security; urgency=low
116

117
118
119
120
121
122
123
124
125
126
127
  * SECURITY UPDATE: New upstream release 5.5.47
    - CVE-2016-0546
    - CVE-2016-0505
    - CVE-2016-0596
    - CVE-2016-0597
    - CVE-2016-0616
    - CVE-2016-0598
    - CVE-2016-0600
    - CVE-2016-0606
    - CVE-2016-0608
    - CVE-2016-0609
128
129
    - CVE-2016-0642
    - CVE-2016-0651
130
    - CVE-2016-2047
131
132
133
134
135
    - Adds the mariadb-slow.log into the logrotate file, as the file
      name mariadb-slow.log is the log name in the default config file.

 -- Otto Kekäläinen <otto@seravo.fi>  Thu, 10 Dec 2015 10:24:40 +0200

136
137
138
mariadb-5.5 (5.5.46-1ubuntu0.14.04.2) trusty-security; urgency=low

  * SECURITY UPDATE: Update to 5.5.46 to fix security issues (LP: #1512241):
139
140
    - CVE-2016-3471
    - CVE-2015-7744
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
    - CVE-2015-4913
    - CVE-2015-4870
    - CVE-2015-4861
    - CVE-2015-4858
    - CVE-2015-4836
    - CVE-2015-4830
    - CVE-2015-4826
    - CVE-2015-4815
    - CVE-2015-4807
    - CVE-2015-4802
    - CVE-2015-4792
  * Upstream release 5.5.45 fixes for the following security vulnerabilities:
    - CVE-2015-4816
    - CVE-2015-4819
    - CVE-2015-4879
  * Update new Oracle CVE identifiers to old MariaDB changelog entries
157
  * New patch: Extend date in test suite so that main.events_1 will pass
158
159
160

 -- Otto Kekäläinen <otto@seravo.fi>  Tue, 03 Nov 2015 11:41:30 +0200

161
mariadb-5.5 (5.5.44-1ubuntu0.14.04.1) trusty-security; urgency=low
Otto Kekäläinen's avatar
Otto Kekäläinen committed
162
163
164

  * SECURITY UPDATE: Update to 5.5.44 to fix security issues (LP: #1464895):
    - CVE-2015-3152
165
166
167
168
    - CVE-2015-2648
    - CVE-2015-2582
    - CVE-2015-4752
    - CVE-2015-2643
169
170
    - CVE-2015-4864
    - CVE-2015-2620
Otto Kekäläinen's avatar
Otto Kekäläinen committed
171
172
173
174
175
  * Upstream also includes lots of line ending changes (from CRLF -> LF)
  * Removed hotfix patch now included in upstream release (MDEV-8115)

 -- Otto Kekäläinen <otto@seravo.fi>  Sat, 13 Jun 2015 21:09:48 +0300

176
mariadb-5.5 (5.5.43-1ubuntu0.14.04.2) trusty-security; urgency=low
177
178
179
180
181
182

  * SECURITY UPDATE: Update to 5.5.43 to fix security issues (LP: #1451677):
    - CVE-2015-0501
    - CVE-2015-2571
    - CVE-2015-0505
    - CVE-2015-0499
183
    - CVE-2015-4757
184
  * Hotfix patch to fix the server crash caused by mysql_upgrade (MDEV-8115)
185
186
187

 -- Otto Kekäläinen <otto@seravo.fi>  Tue, 05 May 2015 09:17:31 +0300

188
mariadb-5.5 (5.5.41-1ubuntu0.14.04.1) trusty-security; urgency=medium
189
190
191
192
193
194
195
196

  * Critical backport from 10.0 (commit 439123d):
    Fix mariadb-server-5.5.postinst so that the flag removal will not emit
    an error code if there are no previous debian-*.flag files (LP: #1417917)

 -- Otto Kekäläinen <otto@seravo.fi>  Wed, 04 Feb 2015 11:28:16 +0200

mariadb-5.5 (5.5.41-0ubuntu0.14.04.2) trusty-security; urgency=medium
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215

  * SECURITY UPDATE: Update to 5.5.41 to fix security issues (LP: #1414755)
    - CVE-2015-0411
    - CVE-2015-0382
    - CVE-2015-0381
    - CVE-2015-0432
    - CVE-2014-6568
    - CVE-2015-0374
  * As approved by Seth Arnold, this security update also imports the latest
    mariadb-5.5 packaging from Debian which includes useful and low-risk
    fixes:
    - Updated Dutch translation by Frans Spiesschaert
    - Updated control file so that mariadb-client-5.5 breaks and replaces
      the package mariadb-server-5.5 to allow overwriting the innochecksum
      man page file which has changed location (LP: #1368124) as per
      doc https://www.debian.org/doc/debian-policy/ch-relationships.html#s7.6.1
    - Backported the fix of #770177 from 10.0 to 5.5 so that the migration
      question will not be asked repeatedly. (LP: #1392539)
   * Close delta between 14.10 and 14.04 in regards of packaging.
216
   * Backported new cacert.pem etc from 5.5 the replace the expired ones
217
218
219

 -- Otto Kekäläinen <otto@seravo.fi>  Tue, 27 Jan 2015 21:15:00 +0200

220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
mariadb-5.5 (5.5.40-0ubuntu0.14.04.1) trusty-security; urgency=medium

  * SECURITY UPDATE: Update to 5.5.40 to fix security issues (LP: #1391676)
    - CVE-2014-6507
    - CVE-2014-6491
    - CVE-2014-6500
    - CVE-2014-6469
    - CVE-2014-6555
    - CVE-2014-6559
    - CVE-2014-6494
    - CVE-2014-6496
    - CVE-2014-6464
  * Add bsdutils as mariadb-server dependency like upstream does in 5.5.40.

 -- Otto Kekäläinen <otto@seravo.fi>  Wed, 12 Oct 2014 01:04:24 +0200

mariadb-5.5 (5.5.39-0ubuntu0.14.04.1) trusty-security; urgency=medium

  * SECURITY UPDATE: Update to 5.5.39 to fix security issues (LP: #1363222)
    * 5.5.39
      - Fixes an error when handling MyISAM temporary files can be
        exploited to execute arbitrary code (Secunia Advisory SA60599)
    * 5.5.38
      - CVE-2014-2494
      - CVE-2014-4207
      - CVE-2014-4243
      - CVE-2014-4258
      - CVE-2014-4260
  * Import a few important packaging bug fixes available in Debian

 -- Otto Kekäläinen <otto@seravo.fi>  Fri, 29 Aug 2014 23:04:24 +0300

mariadb-5.5 (5.5.37-0ubuntu0.14.04.1) trusty-security; urgency=medium

  * SECURITY UPDATE: Update to 5.5.37 to fix security issues (LP: #1313187)
    - http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html
    - CVE-2014-0001
    - CVE-2014-0384
    - CVE-2014-2419
    - CVE-2014-2430
    - CVE-2014-2431
    - CVE-2014-2432
    - CVE-2014-2436
    - CVE-2014-2438
    - CVE-2014-2440

 -- Otto Kekäläinen <otto@seravo.fi>  Mon, 28 Apr 2014 09:55:22 +0300
267

James Page's avatar
James Page committed
268
mariadb-5.5 (5.5.36-1) unstable; urgency=low
269

270
  [ Otto Kekäläinen ]
James Page's avatar
James Page committed
271
272
  * New upstream release.
  * Updated Danish debconf translation (Closes: #739750).
273
  * d/control: Added explicit Conflicts/Replaces for mysql-5.6 packages
James Page's avatar
James Page committed
274
    (Closes: #739841).
275
276
  * d/control: Update for use of virtual-* packages for switching to/from
    MySQL alternatives.
277
278

  [ James Page ]
279
  * d/control: Drop Nicholas from Uploaders, MIA (Closes: #739360).
280
  * d/control: Add libjemalloc-dev to BD's.
281

282
 -- Otto Kekäläinen <otto@seravo.fi>  Sun, 02 Mar 2014 01:38:26 +0200
283

284
285
mariadb-5.5 (5.5.35-1) unstable; urgency=low

286
  [ Otto Kekäläinen ]
287
288
289
290
291
292
293
294
295
296
297
298
299
  * New upstream release, fixing the following security issues:
    - Buffer overflow in client/mysql.cc (Closes: #737597).
      - CVE-2014-0001
    - http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
      - CVE-2013-5891
      - CVE-2013-5908
      - CVE-2014-0386
      - CVE-2014-0393
      - CVE-2014-0401
      - CVE-2014-0402
      - CVE-2014-0412
      - CVE-2014-0420
      - CVE-2014-0437
300
301
302
303
304
  * Upstream https://mariadb.atlassian.net/browse/MDEV-4902
    fixes compatibility with Bison 3.0 (Closes: #733002)
  * Updated Russian debconf translation (Closes: #734426)
  * Updated Japanese debconf translation (Closes: #735284)
  * Updated French debconf translation (Closes: #736480)
305
  * Renamed SONAME properly (Closes: #732967)
306

307
 -- James Page <jamespage@debian.org>  Mon, 17 Feb 2014 16:51:52 +0000
308

309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
mariadb-5.5 (5.5.32-1) unstable; urgency=low

  [ Otto Kekäläinen ]
  * Initial package for Debian (Closes: #565308), based on upstream
    packaging:
    - mariadb-5.3 by Sergei Golubchik
    - mariadb-5.2 by Kristian Nielsen
    - mariadb-5.1 by Peter Lieverdink
  * Bring packaging up-to-date inline with mysql-5.5 packaging.
  * Refine control file and tidy lintian warnings
  * Rename libmysqlclient18 -> libmariadbclient18.
  * Add suitable Breaks/Replaces/Provides to support migration
    to/from mysql-server-5.5.
  * Plus multiple other updates based on feedback from Debian maintainers

  [ James Page ]
  * d/control,rules: Cherry picked fix from mysql-5.5 packaging to disable
    x86 assembler in taocrypt on i386 architectures, removing need for
    gcc-4.4 dependency.
  * d/control: Add myself to uploaders.
  * d/control: Update Vcs fields for new location on git.debian.org.

 -- Otto Kekäläinen <otto@seravo.fi>  Tue, 24 Sept 2013 15:09:51 +0300