-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2018-77e610115a 2018-08-31 21:16:09.272244 --------------------------------------------------------------------------------
Name : mariadb Product : Fedora 28 Version : 10.2.17 Release : 1.fc28 URL : http://mariadb.org Summary : A community developed branch of MySQL Description : MariaDB is a community developed branch of MySQL. MariaDB is a multi-user, multi-threaded SQL database server. It is a client/server implementation consisting of a server daemon (mysqld) and many different client programs and libraries. The base package contains the standard MariaDB/MySQL client programs and generic MySQL files.
-------------------------------------------------------------------------------- Update Information:
**MariaDB 10.2.17 ** Release notes: https://mariadb.com/kb/en/library/mariadb-10217-release-notes/ CVEs fixed: CVE-2018-3060 CVE-2018-3064 CVE-2018-3063 CVE-2018-3058 CVE-2018-3066 CVE-2018-3081 -------------------------------------------------------------------------------- ChangeLog:
* Mon Aug 20 2018 Michal Schorm mschorm@redhat.com - 3:10.2.17-1 - Rebase to 10.2.17 - CVEs fixed: #1602428 CVE-2018-3060 CVE-2018-3064 CVE-2018-3063 CVE-2018-3058 CVE-2018-3066 - CVEs fixed: #1564966 CVE-2018-2767 - CVEs fixed: #1616261 CVE-2018-3081 * Sat Jun 30 2018 Michal Schorm mschorm@redhat.com - 3:10.2.16-1 - Rebase to 10.2.16 MyRocks is now Stable (GA) * Tue Jun 5 2018 Honza Horak hhorak@redhat.com - 3:10.2.15-2 - Use mysqladmin for checking the socket - Jemalloc dependency moved to the TokuDB subpackage. CMake jemalloc option removed, not used anymore. The server doesn't need jemalloc since 10.2: https://jira.mariadb.org/browse/MDEV-11059 - Build MariaDB with TokuDB without Jemalloc. * Wed May 23 2018 Michal Schorm mschorm@redhat.com - 3:10.2.15-1 - Rebase to 10.2.15 - CVEs fixed: #1568962 CVE-2018-2755 CVE-2018-2761 CVE-2018-2766 CVE-2018-2771 CVE-2018-2781 CVE-2018-2782 CVE-2018-2784 CVE-2018-2787 CVE-2018-2813 CVE-2018-2817 CVE-2018-2819 CVE-2018-2786 CVE-2018-2759 CVE-2018-2777 CVE-2018-2810 -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1616261 - CVE-2018-3081 mariadb-connector-c: mysql: Client programs unspecified vulnerability (CPU Jul 2018) [fedora-27] https://bugzilla.redhat.com/show_bug.cgi?id=1616261 [ 2 ] Bug #1564966 - CVE-2018-2767 mariadb: mysql: use of SSL/TLS not enforced in libmysqld (Return of BACKRONYM) [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1564966 [ 3 ] Bug #1602428 - CVE-2018-3058 CVE-2018-3063 CVE-2018-3064 CVE-2018-3066 CVE-2018-3081 mariadb: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1602428 --------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-77e610115a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys --------------------------------------------------------------------------------
package-announce@lists.fedoraproject.org