Bug 211274 - databases/mariadb*-server: Multiple vulnerabilities
Summary: databases/mariadb*-server: Multiple vulnerabilities
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: Normal Affects Many People
Assignee: Bernard Spil
Keywords: needs-patch, needs-qa, security
Depends on:
Blocks: 211248
  Show dependency treegraph
Reported: 2016-07-21 14:41 UTC by Bernard Spil
Modified: 2016-08-08 09:59 UTC (History)
4 users (show)

See Also:
koobs: merge-quarterly?


Note You need to log in before you can comment on or make changes to this bug.
Description Bernard Spil freebsd_committer freebsd_triage 2016-07-21 14:41:33 UTC
MySQL is affected by 22 newly released vulnerabilities.

Assumption is that all versions of MariaDB are also affected
Comment 1 Kubilay Kocak freebsd_committer freebsd_triage 2016-07-22 03:41:13 UTC
Assign to maintainer
Comment 2 Naram Qashat 2016-08-06 16:30:41 UTC

I'd like to point out, based on the link to Oracle in bug #211248 and the above from MariaDB, they say that MariaDB is based off of MySQL 5.5 and is not affected by vulnerabilities in MySQL 5.6 or MySQL 5.7. Furthermore, all the MySQL 5.5 vulnerabilities have been fixed in the versions of the MariaDB ports that are currently in the ports tree. I think the vuxml entries for the MariaDB ports needs to be corrected as a result.
Comment 3 Mark Felder freebsd_committer freebsd_triage 2016-08-06 21:36:46 UTC
MariaDB has several versions that roughly coordinate with MySQL versions. I believe it looks like this:

MariaDB 5.1 == MySQL 5.1
MariaDB 5.2 and 5.3 == MySQL 5.1 + 5.5 backports
MariaDB 5.5 == MySQL 5.5
MariaDB 10.0 ~= MySQL 5.6 (not quite everything pulled in)
MariaDB 10.1 -- not sure? Between MySQL 5.7 and 6.0?

MariaDB isn't quite as different from MariaDB as one might think. We're talking about feature differences while the core is largely identical. If MySQL has a vulnerability, it's extremely likely it's also in MariaDB.
Comment 4 commit-hook freebsd_committer freebsd_triage 2016-08-08 09:58:34 UTC
A commit references this bug:

Author: brnrd
Date: Mon Aug  8 09:58:16 UTC 2016
New revision: 419813
URL: https://svnweb.freebsd.org/changeset/ports/419813

  security/vuxml: Add versions for lates MariaDB vulns

  PR:		211274
