Bug 212616 - databases/mariadb100-server: CVE 2016-6662
Summary: databases/mariadb100-server: CVE 2016-6662
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: --- Affects Many People
Assignee: Bernard Spil
URL: http://legalhackers.com/advisories/My...
Keywords: security
Depends on:
Blocks: 212606
  Show dependency treegraph
 
Reported: 2016-09-12 17:21 UTC by Markus Kohlmeyer
Modified: 2016-09-28 19:11 UTC (History)
1 user (show)

See Also:
bugzilla: maintainer-feedback? (brnrd)
koobs: merge-quarterly?


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Markus Kohlmeyer 2016-09-12 17:21:12 UTC
+++ This bug was initially created as a clone of Bug #212606 +++

Cite from linked advisory:


I. VULNERABILITY
-------------------------

MySQL  <= 5.7.15       Remote Root Code Execution / Privilege Escalation (0day)
	  5.6.33
 	  5.5.52

MySQL clones are also affected, including:

MariaDB
PerconaDB
Comment 1 Bernard Spil freebsd_committer freebsd_triage 2016-09-13 10:09:14 UTC
MariaDB 10.0.27 already contains a fix for CVE-2016-6662
https://mariadb.com/kb/en/mariadb/mariadb-10027-release-notes/
Comment 2 Kubilay Kocak freebsd_committer freebsd_triage 2016-09-13 10:34:20 UTC
@Bernard, please confirm the update has been merged to the quarterly branch. Rejected is probably not the best resolution in this case. Either use "FIXED" with a comment including the commits (initial/merge) that resolved the security issue, or Not a Bug with the same. I think the former is clearer.
Comment 3 Bernard Spil freebsd_committer freebsd_triage 2016-09-14 07:14:31 UTC
This was already fixed in 10.0.27 (2016-08-29)
http://svnweb.freebsd.org/changeset/ports/421088

MFH request pending
Comment 4 Bernard Spil freebsd_committer freebsd_triage 2016-09-28 19:10:48 UTC
Merged 2016Q3

Closed by ports r422134
Comment 5 Bernard Spil freebsd_committer freebsd_triage 2016-09-28 19:11:09 UTC
Merged 2016Q3

Closed by ports r422134