Bug 218934 - databases/mysql57-server: Quarterly (2017Q2) branch version vulnerable
Summary: databases/mysql57-server: Quarterly (2017Q2) branch version vulnerable
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: Normal Affects Many People
Assignee: Mahdi Mokhtari
URL:
Keywords: needs-qa, security
Depends on:
Blocks:
 
Reported: 2017-04-28 12:57 UTC by Denny Höglund
Modified: 2017-04-29 05:49 UTC (History)
1 user (show)

See Also:
mmokhi: maintainer-feedback+
mmokhi: merge-quarterly+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Denny Höglund 2017-04-28 12:57:10 UTC
The 2017Q2 branch only offers mysql57-server-5.7.17 whereas this verison has several vilnerabilities: 
https://vuxml.freebsd.org/freebsd/d9e01c35-2531-11e7-b291-b499baebfeaf.html

Is it possible to add mysql57-server-5.7.18 to the 2017Q2 branch?
Comment 1 Mahdi Mokhtari freebsd_committer freebsd_triage 2017-04-28 21:06:01 UTC
Hi, :-)
I just notified my my mentor from portmgr and sec-team.
I'm waiting for feedback from them.
Comment 2 Kubilay Kocak freebsd_committer freebsd_triage 2017-04-29 05:16:23 UTC
@Mahdi Please add the review URL to the URL field when created
Comment 3 Mahdi Mokhtari freebsd_committer freebsd_triage 2017-04-29 05:36:54 UTC
(In reply to Kubilay Kocak from comment #2)
Approved by feld@ via email.
Should I paste review of the 5.7.18 of HEAD instead?
Comment 4 commit-hook freebsd_committer freebsd_triage 2017-04-29 05:48:35 UTC
A commit references this bug:

Author: mmokhi
Date: Sat Apr 29 05:47:31 UTC 2017
New revision: 439718
URL: https://svnweb.freebsd.org/changeset/ports/439718

Log:
  MFH: r438699

  databases/mysql57-{server client}: Update to latest 5.7.18 release
  Fix some no-longer-valid (but needed) patches.

  Reviewed by:	feld, mat (mentors)
  Approved by:	feld (mentor)
  Differential Revision:	https://reviews.freebsd.org/D10392

  PR:             218934
  Approved by:	ports-secteam (feld)

Changes:
_U  branches/2017Q2/
  branches/2017Q2/databases/mysql57-client/Makefile
  branches/2017Q2/databases/mysql57-client/files/patch-support-files_CMakeLists.txt
  branches/2017Q2/databases/mysql57-server/Makefile
  branches/2017Q2/databases/mysql57-server/distinfo
  branches/2017Q2/databases/mysql57-server/files/patch-rapid_plugin_x_CMakeLists.txt
  branches/2017Q2/databases/mysql57-server/files/patch-sql_conn__handler_socket__connection.cc
  branches/2017Q2/databases/mysql57-server/pkg-plist
Comment 5 Mahdi Mokhtari freebsd_committer freebsd_triage 2017-04-29 05:49:50 UTC
Committed, Thanks :-)