-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2018-d1c4a4ca50 2018-08-31 20:02:40.219639 --------------------------------------------------------------------------------
Name : mariadb Product : Fedora 27 Version : 10.2.17 Release : 1.fc27 URL : http://mariadb.org Summary : A community developed branch of MySQL Description : MariaDB is a community developed branch of MySQL. MariaDB is a multi-user, multi-threaded SQL database server. It is a client/server implementation consisting of a server daemon (mysqld) and many different client programs and libraries. The base package contains the standard MariaDB/MySQL client programs and generic MySQL files.
-------------------------------------------------------------------------------- Update Information:
**MariaDB 10.2.17 ** Release notes: https://mariadb.com/kb/en/library/mariadb-10217-release-notes/ CVEs fixed: CVE-2018-3060 CVE-2018-3064 CVE-2018-3063 CVE-2018-3058 CVE-2018-3066 CVE-2018-3081 -------------------------------------------------------------------------------- ChangeLog:
* Mon Aug 20 2018 Michal Schorm mschorm@redhat.com - 3:10.2.17-1 - Rebase to 10.2.17 - CVEs fixed: #1602428 CVE-2018-3060 CVE-2018-3064 CVE-2018-3063 CVE-2018-3058 CVE-2018-3066 - CVEs fixed: #1564966 CVE-2018-2767 - CVEs fixed: #1616261 CVE-2018-3081 * Sat Jun 30 2018 Michal Schorm mschorm@redhat.com - 3:10.2.16-1 - Rebase to 10.2.16 MyRocks is now Stable (GA) * Tue Jun 5 2018 Honza Horak hhorak@redhat.com - 3:10.2.15-2 - Use mysqladmin for checking the socket - Jemalloc dependency moved to the TokuDB subpackage. CMake jemalloc option removed, not used anymore. The server doesn't need jemalloc since 10.2: https://jira.mariadb.org/browse/MDEV-11059 - Build MariaDB with TokuDB without Jemalloc. * Wed May 23 2018 Michal Schorm mschorm@redhat.com - 3:10.2.15-1 - Rebase to 10.2.15 - CVEs fixed: #1568962 CVE-2018-2755 CVE-2018-2761 CVE-2018-2766 CVE-2018-2771 CVE-2018-2781 CVE-2018-2782 CVE-2018-2784 CVE-2018-2787 CVE-2018-2813 CVE-2018-2817 CVE-2018-2819 CVE-2018-2786 CVE-2018-2759 CVE-2018-2777 CVE-2018-2810 * Thu Mar 29 2018 Michal Schorm mschorm@redhat.com - 3:10.2.14-1 - Rebase to 10.2.14 - Update testsuite run for SSL self signed certificates * Tue Mar 6 2018 Michal Schorm mschorm@redhat.com - 3:10.2.13-2 - Further fix of ldconfig scriptlets for F27 - Fix hardcoded paths, move unversioned libraries and symlinks to the devel subpackage * Thu Mar 1 2018 Michal Schorm mschorm@redhat.com - 3:10.2.13-1 - Rebase to 10.2.13 * Mon Feb 26 2018 Michal Schorm mschorm@redhat.com - 3:10.2.12-8 - SPECfile refresh, RHEL6, SySV init and old fedora stuff removed * Sun Feb 25 2018 Michal Schorm mschorm@redhat.com - 3:10.2.12-7 - Rebuilt for ldconfig_post and ldconfig_postun bug Related: #1548331 * Thu Feb 8 2018 Fedora Release Engineering releng@fedoraproject.org - 3:10.2.12-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild * Fri Jan 26 2018 Michal Schorm mschorm@redhat.com - 3:10.2.12-5 - Use '-ldl' compiler flag when associated library used Resolves: #1538990 * Thu Jan 25 2018 Michal Schorm mschorm@redhat.com - 3:10.2.12-4 - Fix the upgrade path. Build TokuDB subpackage again, but build a unsupported configuration by upstream (without Jemalloc). Jemmalloc has been updated to version 5, which isn't backwards compatible. - Use downstream tmpfiles instead of the upstream one Related: #1538066 * Sat Jan 20 2018 Bj��rn Esser besser82@fedoraproject.org - 3:10.2.12-3 - Rebuilt for switch to libxcrypt * Thu Jan 11 2018 Honza Horak hhorak@redhat.com - 3:10.2.12-1 - Do not build connect plugin with mongo and jdbc connectors - Support MYSQLD_OPTS and _WSREP_NEW_CLUSTER env vars in init script, same as it is done in case of systemd unit file Related: #1455850 - Print the same messages as before when starting the service in SysV init, to not scare users Related: #1463411 * Wed Jan 10 2018 Michal Schorm mschorm@redhat.com - 3:10.2.12-1 - Rebase to 10.2.12 - Temporary fix for https://jira.mariadb.org/browse/MDEV-14537 removed - TokuDB disabled * Mon Dec 11 2017 Michal Schorm mschorm@redhat.com - 3:10.2.11-2 - Temporary fix for #1523875 removed, bug in Annobin fixed Resolves: #1523875 * Sat Dec 9 2017 Michal Schorm mschorm@redhat.com - 3:10.2.11-1 - Rebase to 10.2.11 - Temporary fix for https://jira.mariadb.org/browse/MDEV-14537 introduced - Temporary fix for #1523875 intoruced Related: #1523875 * Wed Dec 6 2017 Michal Schorm mschorm@redhat.com - 3:10.2.10-2 - Fix PID file location Related: #1483331, #1515779 - Remove 'Group' tags as they should not be used any more Related: https://fedoraproject.org/wiki/RPMGroups * Mon Nov 20 2017 Michal Schorm mschorm@redhat.com - 3:10.2.10-1 - Rebase to 10.2.10 version - Patch 2: mariadb-install-test.patch has been incorporated by upstream - Patch 8: mariadb-install-db-sharedir.patch; upstream started to use macros - Update PCRE check - Start using location libdir/mariadb for plugins - Move libraries to libdir - Divided to more sub-packages to match upstream's RPM list Resolves: #1490401; #1400463 - Update of Cmake arguments to supported format Related: https://lists.launchpad.net/maria-discuss/msg04852.html - Remove false Provides -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1616261 - CVE-2018-3081 mariadb-connector-c: mysql: Client programs unspecified vulnerability (CPU Jul 2018) [fedora-27] https://bugzilla.redhat.com/show_bug.cgi?id=1616261 [ 2 ] Bug #1564966 - CVE-2018-2767 mariadb: mysql: use of SSL/TLS not enforced in libmysqld (Return of BACKRONYM) [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1564966 [ 3 ] Bug #1602428 - CVE-2018-3058 CVE-2018-3063 CVE-2018-3064 CVE-2018-3066 CVE-2018-3081 mariadb: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1602428 --------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-d1c4a4ca50' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys --------------------------------------------------------------------------------