Security fixes from the April 2017 CPU

Debian Bug report logs - #860544
Security fixes from the April 2017 CPU

version graph

Reported by: "Norvald H. Ryeng" <norvald.ryeng@oracle.com>

Date: Tue, 18 Apr 2017 11:30:01 UTC

Severity: grave

Tags: fixed-upstream, security, upstream

Found in versions mysql-5.5/5.5.23-2, mysql-5.5/5.5.54-0+deb8u1

Fixed in version mysql-5.5/5.5.55-0+deb8u1

Done: Lars Tangvald <lars.tangvald@oracle.com>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, Debian MySQL Maintainers <pkg-mysql-maint@lists.alioth.debian.org>:
Bug#860544; Package src:mysql-5.5. (Tue, 18 Apr 2017 11:30:04 GMT) (full text, mbox, link).


Acknowledgement sent to "Norvald H. Ryeng" <norvald.ryeng@oracle.com>:
New Bug report received and forwarded. Copy sent to Debian MySQL Maintainers <pkg-mysql-maint@lists.alioth.debian.org>. (Tue, 18 Apr 2017 11:30:04 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: "Norvald H. Ryeng" <norvald.ryeng@oracle.com>
To: submit@bugs.debian.org
Subject: Security fixes from the April 2017 CPU
Date: Tue, 18 Apr 2017 13:26:23 +0200
Source: mysql-5.5
Version: 5.5.54-0+deb8u1
Severity: grave
Tags: security upstream fixed-upstream

The Oracle Critical Patch Update for April 2017 will be released on  
Tuesday, April 18. According to the pre-release announcement [1], it  
will contain information about CVEs fixed in MySQL 5.5.55.

The CVE numbers will be available when the CPU is released.

Please note that the MySQL release cycle has changed from every two
months to every three months. The releases are now synchronized with
the CPU announcements.

Best regards,

Norvald H. Ryeng

[1] http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html



Information forwarded to debian-bugs-dist@lists.debian.org, Debian MySQL Maintainers <pkg-mysql-maint@lists.alioth.debian.org>:
Bug#860544; Package src:mysql-5.5. (Wed, 19 Apr 2017 05:39:03 GMT) (full text, mbox, link).


Acknowledgement sent to Lars Tangvald <lars.tangvald@oracle.com>:
Extra info received and forwarded to list. Copy sent to Debian MySQL Maintainers <pkg-mysql-maint@lists.alioth.debian.org>. (Wed, 19 Apr 2017 05:39:03 GMT) (full text, mbox, link).


Message #10 received at 860544@bugs.debian.org (full text, mbox, reply):

From: Lars Tangvald <lars.tangvald@oracle.com>
To: <860544@bugs.debian.org>
Subject: Re: [debian-mysql] Bug#860544: Security fixes from the April 2017 CPU
Date: Tue, 18 Apr 2017 22:34:11 -0700 (PDT)
CVE list for 5.5:

CVE-2017-3302
CVE-2017-3305
CVE-2017-3308
CVE-2017-3309
CVE-2017-3329
CVE-2017-3453
CVE-2017-3456
CVE-2017-3461
CVE-2017-3462
CVE-2017-3463
CVE-2017-3464
CVE-2017-3600

--
Lars



Information forwarded to debian-bugs-dist@lists.debian.org, Debian MySQL Maintainers <pkg-mysql-maint@lists.alioth.debian.org>:
Bug#860544; Package src:mysql-5.5. (Wed, 19 Apr 2017 06:51:04 GMT) (full text, mbox, link).


Acknowledgement sent to Lars Tangvald <lars.tangvald@oracle.com>:
Extra info received and forwarded to list. Copy sent to Debian MySQL Maintainers <pkg-mysql-maint@lists.alioth.debian.org>. (Wed, 19 Apr 2017 06:51:04 GMT) (full text, mbox, link).


Message #15 received at 860544@bugs.debian.org (full text, mbox, reply):

From: Lars Tangvald <lars.tangvald@oracle.com>
To: <860544@bugs.debian.org>, <norvald.ryeng@oracle.com>
Subject: Re: [debian-mysql] Bug#860544: Security fixes from the April 2017 CPU
Date: Tue, 18 Apr 2017 22:18:05 -0700 (PDT)
Hei,

Denne patchen: https://anonscm.debian.org/cgit/pkg-mysql/mysql-5.5.git/tree/debian/patches/fix_use_after_free_in_mysql_prune_stmt_list.patch?h=debian/wheezy
Ble lagt til (kun debian 7) for 5.5.54, og får konflikt i 5.5.55. Har du tid til å ta en titt og evt. lage oppdatert patch?

--
Lars
----- norvald.ryeng@oracle.com wrote:

> Source: mysql-5.5
> Version: 5.5.54-0+deb8u1
> Severity: grave
> Tags: security upstream fixed-upstream
> 
> The Oracle Critical Patch Update for April 2017 will be released on  
> Tuesday, April 18. According to the pre-release announcement [1], it 
> 
> will contain information about CVEs fixed in MySQL 5.5.55.
> 
> The CVE numbers will be available when the CPU is released.
> 
> Please note that the MySQL release cycle has changed from every two
> months to every three months. The releases are now synchronized with
> the CPU announcements.
> 
> Best regards,
> 
> Norvald H. Ryeng
> 
> [1]
> http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html
> 
> _______________________________________________
> pkg-mysql-maint mailing list
> pkg-mysql-maint@lists.alioth.debian.org
> http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-mysql-maint



Information forwarded to debian-bugs-dist@lists.debian.org, Debian MySQL Maintainers <pkg-mysql-maint@lists.alioth.debian.org>:
Bug#860544; Package src:mysql-5.5. (Wed, 19 Apr 2017 07:00:45 GMT) (full text, mbox, link).


Acknowledgement sent to Lars Tangvald <lars.tangvald@oracle.com>:
Extra info received and forwarded to list. Copy sent to Debian MySQL Maintainers <pkg-mysql-maint@lists.alioth.debian.org>. (Wed, 19 Apr 2017 07:00:45 GMT) (full text, mbox, link).


Message #20 received at 860544@bugs.debian.org (full text, mbox, reply):

From: Lars Tangvald <lars.tangvald@oracle.com>
To: <860544@bugs.debian.org>, <norvald.ryeng@oracle.com>
Subject: Re: [debian-mysql] Bug#860544: Security fixes from the April 2017 CPU
Date: Tue, 18 Apr 2017 22:19:47 -0700 (PDT)
Whoops, that went to the wrong address...

Message just says that a patch added by the lts team to 5.5.54 doesn't apply on 5.5.55 :)

--
Lars
----- lars.tangvald@oracle.com wrote:

> Hei,
> 
> Denne patchen:
> https://anonscm.debian.org/cgit/pkg-mysql/mysql-5.5.git/tree/debian/patches/fix_use_after_free_in_mysql_prune_stmt_list.patch?h=debian/wheezy
> Ble lagt til (kun debian 7) for 5.5.54, og får konflikt i 5.5.55. Har
> du tid til å ta en titt og evt. lage oppdatert patch?
> 
> --
> Lars
> ----- norvald.ryeng@oracle.com wrote:
> 
> > Source: mysql-5.5
> > Version: 5.5.54-0+deb8u1
> > Severity: grave
> > Tags: security upstream fixed-upstream
> > 
> > The Oracle Critical Patch Update for April 2017 will be released on 
> 
> > Tuesday, April 18. According to the pre-release announcement [1], it
> 
> > 
> > will contain information about CVEs fixed in MySQL 5.5.55.
> > 
> > The CVE numbers will be available when the CPU is released.
> > 
> > Please note that the MySQL release cycle has changed from every two
> > months to every three months. The releases are now synchronized
> with
> > the CPU announcements.
> > 
> > Best regards,
> > 
> > Norvald H. Ryeng
> > 
> > [1]
> >
> http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html
> > 
> > _______________________________________________
> > pkg-mysql-maint mailing list
> > pkg-mysql-maint@lists.alioth.debian.org
> >
> http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-mysql-maint



Information forwarded to debian-bugs-dist@lists.debian.org, Debian MySQL Maintainers <pkg-mysql-maint@lists.alioth.debian.org>:
Bug#860544; Package src:mysql-5.5. (Wed, 19 Apr 2017 07:45:06 GMT) (full text, mbox, link).


Acknowledgement sent to "Norvald H. Ryeng" <norvald.ryeng@oracle.com>:
Extra info received and forwarded to list. Copy sent to Debian MySQL Maintainers <pkg-mysql-maint@lists.alioth.debian.org>. (Wed, 19 Apr 2017 07:45:06 GMT) (full text, mbox, link).


Message #25 received at 860544@bugs.debian.org (full text, mbox, reply):

From: "Norvald H. Ryeng" <norvald.ryeng@oracle.com>
To: Lars Tangvald <lars.tangvald@oracle.com>
Cc: <860544@bugs.debian.org>
Subject: Re: [debian-mysql] Bug#860544: Security fixes from the April 2017 CPU
Date: Wed, 19 Apr 2017 09:23:41 +0200
On Tue, 18 Apr 2017 22:19:47 -0700 (PDT)
Lars Tangvald <lars.tangvald@oracle.com> wrote:

> Whoops, that went to the wrong address...
> 
> Message just says that a patch added by the lts team to 5.5.54
> doesn't apply on 5.5.55 :)

The patch is no longer necessary. The bug has been fixed in 5.5.55.

Best regards,

Norvald H. Ryeng



Information forwarded to debian-bugs-dist@lists.debian.org, Debian MySQL Maintainers <pkg-mysql-maint@lists.alioth.debian.org>:
Bug#860544; Package src:mysql-5.5. (Wed, 19 Apr 2017 11:36:05 GMT) (full text, mbox, link).


Acknowledgement sent to Lars Tangvald <lars.tangvald@oracle.com>:
Extra info received and forwarded to list. Copy sent to Debian MySQL Maintainers <pkg-mysql-maint@lists.alioth.debian.org>. (Wed, 19 Apr 2017 11:36:05 GMT) (full text, mbox, link).


Message #30 received at 860544@bugs.debian.org (full text, mbox, reply):

From: Lars Tangvald <lars.tangvald@oracle.com>
To: Team <team@security.debian.org>
Cc: <860544@bugs.debian.org>
Subject: Re: [debian-mysql] Bug#860544: Security fixes from the April 2017 CPU
Date: Wed, 19 Apr 2017 04:26:30 -0700 (PDT)
[Message part 1 (text/plain, inline)]
Hi,


We've prepared and tested the update to MySQL 5.5.55 for Jessie. Debdiff output is attached.
Only packaging changes are one refreshed patch and one that is no longer needed (5.5.54 for Wheezy had an additional patch added, which is also no longer needed).

--
Lars
[jessiedebiandiff.txt (text/plain, attachment)]
[jessiedebdiff.txt.gz (application/gzip, attachment)]

Information forwarded to debian-bugs-dist@lists.debian.org, Debian MySQL Maintainers <pkg-mysql-maint@lists.alioth.debian.org>:
Bug#860544; Package src:mysql-5.5. (Wed, 19 Apr 2017 13:33:04 GMT) (full text, mbox, link).


Acknowledgement sent to Salvatore Bonaccorso <carnil@debian.org>:
Extra info received and forwarded to list. Copy sent to Debian MySQL Maintainers <pkg-mysql-maint@lists.alioth.debian.org>. (Wed, 19 Apr 2017 13:33:04 GMT) (full text, mbox, link).


Message #35 received at 860544@bugs.debian.org (full text, mbox, reply):

From: Salvatore Bonaccorso <carnil@debian.org>
To: Lars Tangvald <lars.tangvald@oracle.com>
Cc: Team <team@security.debian.org>, 860544@bugs.debian.org
Subject: Re: [debian-mysql] Bug#860544: Security fixes from the April 2017 CPU
Date: Wed, 19 Apr 2017 15:30:39 +0200
Hi Lars,

On Wed, Apr 19, 2017 at 04:26:30AM -0700, Lars Tangvald wrote:
> Hi,
> 
> 
> We've prepared and tested the update to MySQL 5.5.55 for Jessie.
> Debdiff output is attached.
> Only packaging changes are one refreshed patch and one that is no
> longer needed (5.5.54 for Wheezy had an additional patch added,
> which is also no longer needed).

Thanks for preparing the update.

CVE-2017-3302 is as well know nin BTS as #854713, can you add a bug closer for
this one as well? If it's too much of hassle, then leave it, and we close it
manually.

Ok, please upload to security-master.

Regards,
Salvatore



Information forwarded to debian-bugs-dist@lists.debian.org, Debian MySQL Maintainers <pkg-mysql-maint@lists.alioth.debian.org>:
Bug#860544; Package src:mysql-5.5. (Wed, 19 Apr 2017 19:27:11 GMT) (full text, mbox, link).


Acknowledgement sent to Lars Tangvald <lars.tangvald@oracle.com>:
Extra info received and forwarded to list. Copy sent to Debian MySQL Maintainers <pkg-mysql-maint@lists.alioth.debian.org>. (Wed, 19 Apr 2017 19:27:11 GMT) (full text, mbox, link).


Message #40 received at 860544@bugs.debian.org (full text, mbox, reply):

From: Lars Tangvald <lars.tangvald@oracle.com>
To: <carnil@debian.org>
Cc: <team@security.debian.org>, <860544@bugs.debian.org>
Subject: Re: [debian-mysql] Bug#860544: Security fixes from the April 2017 CPU
Date: Wed, 19 Apr 2017 12:24:25 -0700 (PDT)
Hi,
----- carnil@debian.org wrote:

> Hi Lars,
> 
> On Wed, Apr 19, 2017 at 04:26:30AM -0700, Lars Tangvald wrote:
> > Hi,
> > 
> > 
> > We've prepared and tested the update to MySQL 5.5.55 for Jessie.
> > Debdiff output is attached.
> > Only packaging changes are one refreshed patch and one that is no
> > longer needed (5.5.54 for Wheezy had an additional patch added,
> > which is also no longer needed).
> 
> Thanks for preparing the update.
> 
> CVE-2017-3302 is as well know nin BTS as #854713, can you add a bug
> closer for
> this one as well? If it's too much of hassle, then leave it, and we
> close it
> manually.
> 
> Ok, please upload to security-master.
> 
> Regards,
> Salvatore

Ah right, that's the bug for the patch in the Wheezy 5.5.54 packages. I'll add it.

--
Lars



Information forwarded to debian-bugs-dist@lists.debian.org, Debian MySQL Maintainers <pkg-mysql-maint@lists.alioth.debian.org>:
Bug#860544; Package src:mysql-5.5. (Fri, 21 Apr 2017 04:09:02 GMT) (full text, mbox, link).


Acknowledgement sent to Lars Tangvald <lars.tangvald@oracle.com>:
Extra info received and forwarded to list. Copy sent to Debian MySQL Maintainers <pkg-mysql-maint@lists.alioth.debian.org>. (Fri, 21 Apr 2017 04:09:02 GMT) (full text, mbox, link).


Message #45 received at 860544@bugs.debian.org (full text, mbox, reply):

From: Lars Tangvald <lars.tangvald@oracle.com>
To: Salvatore Bonaccorso <carnil@debian.org>
Cc: Team <team@security.debian.org>, 860544@bugs.debian.org
Subject: Re: [debian-mysql] Bug#860544: Security fixes from the April 2017 CPU
Date: Fri, 21 Apr 2017 06:07:40 +0200
Hi,

I lost internet connectivity where I am right now, so probably unable to 
get this done until Monday. Could maybe use the previous debdiff for 
Jessie if you're ok with closing the bug manually.
Also, I think we still don't have any active members in the maintainer 
team with upload access for 5.5

--
Lars

On 19. april 2017 15:30, Salvatore Bonaccorso wrote:
> Hi Lars,
>
> On Wed, Apr 19, 2017 at 04:26:30AM -0700, Lars Tangvald wrote:
>> Hi,
>>
>>
>> We've prepared and tested the update to MySQL 5.5.55 for Jessie.
>> Debdiff output is attached.
>> Only packaging changes are one refreshed patch and one that is no
>> longer needed (5.5.54 for Wheezy had an additional patch added,
>> which is also no longer needed).
> Thanks for preparing the update.
>
> CVE-2017-3302 is as well know nin BTS as #854713, can you add a bug closer for
> this one as well? If it's too much of hassle, then leave it, and we close it
> manually.
>
> Ok, please upload to security-master.
>
> Regards,
> Salvatore




Information forwarded to debian-bugs-dist@lists.debian.org, Debian MySQL Maintainers <pkg-mysql-maint@lists.alioth.debian.org>:
Bug#860544; Package src:mysql-5.5. (Fri, 21 Apr 2017 06:09:02 GMT) (full text, mbox, link).


Acknowledgement sent to Salvatore Bonaccorso <carnil@debian.org>:
Extra info received and forwarded to list. Copy sent to Debian MySQL Maintainers <pkg-mysql-maint@lists.alioth.debian.org>. (Fri, 21 Apr 2017 06:09:02 GMT) (full text, mbox, link).


Message #50 received at 860544@bugs.debian.org (full text, mbox, reply):

From: Salvatore Bonaccorso <carnil@debian.org>
To: Lars Tangvald <lars.tangvald@oracle.com>
Cc: Team <team@security.debian.org>, 860544@bugs.debian.org
Subject: Re: [debian-mysql] Bug#860544: Security fixes from the April 2017 CPU
Date: Fri, 21 Apr 2017 08:04:58 +0200
Hi Lars,

On Fri, Apr 21, 2017 at 06:07:40AM +0200, Lars Tangvald wrote:
> Hi,
> 
> I lost internet connectivity where I am right now, so probably unable to get
> this done until Monday. Could maybe use the previous debdiff for Jessie if
> you're ok with closing the bug manually.
> Also, I think we still don't have any active members in the maintainer team
> with upload access for 5.5

Okay, I will look if I can take care of the upload for
jessie-security.

Regards,
Salvatore



Information forwarded to debian-bugs-dist@lists.debian.org, Debian MySQL Maintainers <pkg-mysql-maint@lists.alioth.debian.org>:
Bug#860544; Package src:mysql-5.5. (Mon, 24 Apr 2017 06:03:02 GMT) (full text, mbox, link).


Acknowledgement sent to Lars Tangvald <lars.tangvald@oracle.com>:
Extra info received and forwarded to list. Copy sent to Debian MySQL Maintainers <pkg-mysql-maint@lists.alioth.debian.org>. (Mon, 24 Apr 2017 06:03:02 GMT) (full text, mbox, link).


Message #55 received at 860544@bugs.debian.org (full text, mbox, reply):

From: Lars Tangvald <lars.tangvald@oracle.com>
To: Salvatore Bonaccorso <carnil@debian.org>
Cc: Team <team@security.debian.org>, 860544@bugs.debian.org
Subject: Re: [debian-mysql] Bug#860544: Security fixes from the April 2017 CPU
Date: Mon, 24 Apr 2017 07:59:36 +0200
On 04/21/2017 08:04 AM, Salvatore Bonaccorso wrote:
> Hi Lars,
>
> On Fri, Apr 21, 2017 at 06:07:40AM +0200, Lars Tangvald wrote:
>> Hi,
>>
>> I lost internet connectivity where I am right now, so probably unable to get
>> this done until Monday. Could maybe use the previous debdiff for Jessie if
>> you're ok with closing the bug manually.
>> Also, I think we still don't have any active members in the maintainer team
>> with upload access for 5.5
> Okay, I will look if I can take care of the upload for
> jessie-security.
>
> Regards,
> Salvatore

Thanks! I was just about to push the update to git, but I see you 
already did. Do you need anything more from us on this? Working with the 
LTS team for wheezy-security.

--
Lars



Information forwarded to debian-bugs-dist@lists.debian.org, Debian MySQL Maintainers <pkg-mysql-maint@lists.alioth.debian.org>:
Bug#860544; Package src:mysql-5.5. (Mon, 24 Apr 2017 08:30:03 GMT) (full text, mbox, link).


Acknowledgement sent to Salvatore Bonaccorso <carnil@debian.org>:
Extra info received and forwarded to list. Copy sent to Debian MySQL Maintainers <pkg-mysql-maint@lists.alioth.debian.org>. (Mon, 24 Apr 2017 08:30:03 GMT) (full text, mbox, link).


Message #60 received at 860544@bugs.debian.org (full text, mbox, reply):

From: Salvatore Bonaccorso <carnil@debian.org>
To: Lars Tangvald <lars.tangvald@oracle.com>
Cc: Team <team@security.debian.org>, 860544@bugs.debian.org
Subject: Re: [debian-mysql] Bug#860544: Security fixes from the April 2017 CPU
Date: Mon, 24 Apr 2017 10:27:51 +0200
Hi Lars,

On Mon, Apr 24, 2017 at 07:59:36AM +0200, Lars Tangvald wrote:
> 
> 
> On 04/21/2017 08:04 AM, Salvatore Bonaccorso wrote:
> >Hi Lars,
> >
> >On Fri, Apr 21, 2017 at 06:07:40AM +0200, Lars Tangvald wrote:
> >>Hi,
> >>
> >>I lost internet connectivity where I am right now, so probably unable to get
> >>this done until Monday. Could maybe use the previous debdiff for Jessie if
> >>you're ok with closing the bug manually.
> >>Also, I think we still don't have any active members in the maintainer team
> >>with upload access for 5.5
> >Okay, I will look if I can take care of the upload for
> >jessie-security.
> >
> >Regards,
> >Salvatore
> 
> Thanks! I was just about to push the update to git, but I see you already
> did. Do you need anything more from us on this? Working with the LTS team
> for wheezy-security.

No, it's fine at the moment. I'm still waiting for two builds. armhf
furthermore failed. Checking if that was temprary.

Regards,
Salvatore



Information forwarded to debian-bugs-dist@lists.debian.org, Debian MySQL Maintainers <pkg-mysql-maint@lists.alioth.debian.org>:
Bug#860544; Package src:mysql-5.5. (Mon, 24 Apr 2017 08:48:02 GMT) (full text, mbox, link).


Acknowledgement sent to Lars Tangvald <lars.tangvald@oracle.com>:
Extra info received and forwarded to list. Copy sent to Debian MySQL Maintainers <pkg-mysql-maint@lists.alioth.debian.org>. (Mon, 24 Apr 2017 08:48:03 GMT) (full text, mbox, link).


Message #65 received at 860544@bugs.debian.org (full text, mbox, reply):

From: Lars Tangvald <lars.tangvald@oracle.com>
To: Salvatore Bonaccorso <carnil@debian.org>
Cc: Team <team@security.debian.org>, 860544@bugs.debian.org
Subject: Re: [debian-mysql] Bug#860544: Security fixes from the April 2017 CPU
Date: Mon, 24 Apr 2017 10:44:52 +0200
On 04/24/2017 10:27 AM, Salvatore Bonaccorso wrote:
> Hi Lars,
>
> On Mon, Apr 24, 2017 at 07:59:36AM +0200, Lars Tangvald wrote:
>>
>> On 04/21/2017 08:04 AM, Salvatore Bonaccorso wrote:
>>> Hi Lars,
>>>
>>> On Fri, Apr 21, 2017 at 06:07:40AM +0200, Lars Tangvald wrote:
>>>> Hi,
>>>>
>>>> I lost internet connectivity where I am right now, so probably unable to get
>>>> this done until Monday. Could maybe use the previous debdiff for Jessie if
>>>> you're ok with closing the bug manually.
>>>> Also, I think we still don't have any active members in the maintainer team
>>>> with upload access for 5.5
>>> Okay, I will look if I can take care of the upload for
>>> jessie-security.
>>>
>>> Regards,
>>> Salvatore
>> Thanks! I was just about to push the update to git, but I see you already
>> did. Do you need anything more from us on this? Working with the LTS team
>> for wheezy-security.
> No, it's fine at the moment. I'm still waiting for two builds. armhf
> furthermore failed. Checking if that was temprary.
Was it a test failure?
There are some unstable tests I think we should identify (in unstable 
we've started disabling them and reporting upstream bug for each).

--
Lars



Information forwarded to debian-bugs-dist@lists.debian.org, Debian MySQL Maintainers <pkg-mysql-maint@lists.alioth.debian.org>:
Bug#860544; Package src:mysql-5.5. (Mon, 24 Apr 2017 19:00:06 GMT) (full text, mbox, link).


Acknowledgement sent to Salvatore Bonaccorso <carnil@debian.org>:
Extra info received and forwarded to list. Copy sent to Debian MySQL Maintainers <pkg-mysql-maint@lists.alioth.debian.org>. (Mon, 24 Apr 2017 19:00:06 GMT) (full text, mbox, link).


Message #70 received at 860544@bugs.debian.org (full text, mbox, reply):

From: Salvatore Bonaccorso <carnil@debian.org>
To: Lars Tangvald <lars.tangvald@oracle.com>
Cc: Team <team@security.debian.org>, 860544@bugs.debian.org
Subject: Re: [debian-mysql] Bug#860544: Security fixes from the April 2017 CPU
Date: Mon, 24 Apr 2017 20:56:39 +0200
Hi Lars,

On Mon, Apr 24, 2017 at 10:44:52AM +0200, Lars Tangvald wrote:
> 
> 
> On 04/24/2017 10:27 AM, Salvatore Bonaccorso wrote:
> > Hi Lars,
> > 
> > On Mon, Apr 24, 2017 at 07:59:36AM +0200, Lars Tangvald wrote:
> > > 
> > > On 04/21/2017 08:04 AM, Salvatore Bonaccorso wrote:
> > > > Hi Lars,
> > > > 
> > > > On Fri, Apr 21, 2017 at 06:07:40AM +0200, Lars Tangvald wrote:
> > > > > Hi,
> > > > > 
> > > > > I lost internet connectivity where I am right now, so probably unable to get
> > > > > this done until Monday. Could maybe use the previous debdiff for Jessie if
> > > > > you're ok with closing the bug manually.
> > > > > Also, I think we still don't have any active members in the maintainer team
> > > > > with upload access for 5.5
> > > > Okay, I will look if I can take care of the upload for
> > > > jessie-security.
> > > > 
> > > > Regards,
> > > > Salvatore
> > > Thanks! I was just about to push the update to git, but I see you already
> > > did. Do you need anything more from us on this? Working with the LTS team
> > > for wheezy-security.
> > No, it's fine at the moment. I'm still waiting for two builds. armhf
> > furthermore failed. Checking if that was temprary.
> Was it a test failure?
> There are some unstable tests I think we should identify (in unstable we've
> started disabling them and reporting upstream bug for each).

Seems it was temporary, we have now as well the builds for armhf and
ppc64el.

Regards,
Salvatore



Marked as found in versions mysql-5.5/5.5.23-2. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Wed, 26 Apr 2017 05:57:07 GMT) (full text, mbox, link).


Reply sent to Lars Tangvald <lars.tangvald@oracle.com>:
You have taken responsibility. (Fri, 28 Apr 2017 10:36:11 GMT) (full text, mbox, link).


Notification sent to "Norvald H. Ryeng" <norvald.ryeng@oracle.com>:
Bug acknowledged by developer. (Fri, 28 Apr 2017 10:36:11 GMT) (full text, mbox, link).


Message #77 received at 860544-close@bugs.debian.org (full text, mbox, reply):

From: Lars Tangvald <lars.tangvald@oracle.com>
To: 860544-close@bugs.debian.org
Subject: Bug#860544: fixed in mysql-5.5 5.5.55-0+deb8u1
Date: Fri, 28 Apr 2017 10:32:27 +0000
Source: mysql-5.5
Source-Version: 5.5.55-0+deb8u1

We believe that the bug you reported is fixed in the latest version of
mysql-5.5, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 860544@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Lars Tangvald <lars.tangvald@oracle.com> (supplier of updated mysql-5.5 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 18 Apr 2017 09:24:12 +0200
Source: mysql-5.5
Binary: libmysqlclient18 libmysqld-pic libmysqld-dev libmysqlclient-dev mysql-common mysql-client-5.5 mysql-server-core-5.5 mysql-server-5.5 mysql-server mysql-client mysql-testsuite mysql-testsuite-5.5 mysql-source-5.5
Architecture: all source
Version: 5.5.55-0+deb8u1
Distribution: jessie-security
Urgency: high
Maintainer: Debian MySQL Maintainers <pkg-mysql-maint@lists.alioth.debian.org>
Changed-By: Lars Tangvald <lars.tangvald@oracle.com>
Closes: 854713 860544
Description: 
 libmysqlclient-dev - MySQL database development files
 libmysqlclient18 - MySQL database client library
 libmysqld-dev - MySQL embedded database development files
 libmysqld-pic - PIC version of MySQL embedded server development files
 mysql-client - MySQL database client (metapackage depending on the latest versio
 mysql-client-5.5 - MySQL database client binaries
 mysql-common - MySQL database common files, e.g. /etc/mysql/my.cnf
 mysql-server - MySQL database server (metapackage depending on the latest versio
 mysql-server-5.5 - MySQL database server binaries and system database setup
 mysql-server-core-5.5 - MySQL database server binaries
 mysql-source-5.5 - MySQL source
 mysql-testsuite - MySQL testsuite
 mysql-testsuite-5.5 - MySQL testsuite
Changes:
 mysql-5.5 (5.5.55-0+deb8u1) jessie-security; urgency=high
 .
   * Imported upstream version 5.5.55 to fix security issues:
     - http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html
     - CVE-2017-3302 CVE-2017-3305 CVE-2017-3308 CVE-2017-3309
     - CVE-2017-3329 CVE-2017-3453 CVE-2017-3456 CVE-2017-3461
     - CVE-2017-3462 CVE-2017-3463 CVE-2017-3464 CVE-2017-3600
     (Closes: #860544, #854713)
   * d/patches: refreshed 62_disable_tests.patch
   * d/patches: dropped fix_test_events_2.patch. Issue fixed upstream
Checksums-Sha1: 
 0e87be3d9901201d8686248c01138eb2b3ed8de3 3262 mysql-5.5_5.5.55-0+deb8u1.dsc
 8ab934610e09e5325e143680a201d86ba7f2f70d 21040959 mysql-5.5_5.5.55.orig.tar.gz
 8c56d62fda9a53c4cad146e8668998ef5073c13a 232772 mysql-5.5_5.5.55-0+deb8u1.debian.tar.xz
 0c9814f51aea9d5562c917e33e227a0ac305b388 85990 mysql-common_5.5.55-0+deb8u1_all.deb
 109bc8468b6c4801064a680117a3740eef247800 84232 mysql-server_5.5.55-0+deb8u1_all.deb
 266d43a5ea80782f7879184f69ac559aabd7a7cd 84106 mysql-client_5.5.55-0+deb8u1_all.deb
 88770fe124e15a608169ae3d7713b9d30a0a709a 84084 mysql-testsuite_5.5.55-0+deb8u1_all.deb
Checksums-Sha256: 
 52cabbff6950dd73e89db86092c84cd658c49f59120af6eab8b35d4a67e92850 3262 mysql-5.5_5.5.55-0+deb8u1.dsc
 9af0a504e2603b0bc0c7c3a4a747df064fb51670a0022b1ad6114f9058b64171 21040959 mysql-5.5_5.5.55.orig.tar.gz
 7072d8bf9ffbf40ef82d95c0ff8f87a5ef9f84753946a7e3c1a343bb99750401 232772 mysql-5.5_5.5.55-0+deb8u1.debian.tar.xz
 aa45126c71ab1978d3e2d7b2e498ecc55778627a40361c75011a2a631151dcba 85990 mysql-common_5.5.55-0+deb8u1_all.deb
 d9ba8a84584cdff8fd56310da2fd80f18ab9e1543a94b1083f72dd307c8e23ef 84232 mysql-server_5.5.55-0+deb8u1_all.deb
 033c8e0f6b04dfc30a4a443acac568304be5733fd8da8aceeb19004cbb96bc8c 84106 mysql-client_5.5.55-0+deb8u1_all.deb
 0f03018e78290f74e56f56b516d96d36fcb7fc3b8778956184bfa9faa837c375 84084 mysql-testsuite_5.5.55-0+deb8u1_all.deb
Files: 
 82be8dbc29494e30bfaa924f9982b43e 3262 database optional mysql-5.5_5.5.55-0+deb8u1.dsc
 6414b0dc724c1297139991164c4038cc 21040959 database optional mysql-5.5_5.5.55.orig.tar.gz
 72c59e13b8877090dd2924e9bf0c2f5e 232772 database optional mysql-5.5_5.5.55-0+deb8u1.debian.tar.xz
 eac582cf88a7eac7b5c5af97cc1a354a 85990 database optional mysql-common_5.5.55-0+deb8u1_all.deb
 b334505357186fb58ba8ba7d2a587821 84232 database optional mysql-server_5.5.55-0+deb8u1_all.deb
 df9b7e1e68599d6c5ddb6a5102aa6f4f 84106 database optional mysql-client_5.5.55-0+deb8u1_all.deb
 5e509c668d4c5161e3acb06ee05bf86b 84084 database optional mysql-testsuite_5.5.55-0+deb8u1_all.deb

-----BEGIN PGP SIGNATURE-----

iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAlj8YFtfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk
ZWJpYW4ub3JnAAoJEAVMuPMTQ89Et/4P/2sU3A887ku6TR/FpYEC+IYfqCetOOsh
aSZhE6ehC/Gbv450zOg/ReOYVJpkxplAJZh9H2dhljPHvpy/a5TetkE+VWuIp7uG
Y7i/B3fVZEaISVznB799/6WwG/GTKfPXIqYBQnutVuUqMKvflpSB8n50BH7zrWzE
SugKEDzMl649HCd6jdq7o20GysIIgQMdBejTAYnk7iG9hJUKVmXGW3jwfH0gzxM9
ouWItE/ay1QJDj35DxeYNvuMOg3iGHH8N9cjbUKCMmww9d7SO+j1uj+TOff6P2rN
eFlyXk33pCqbMw6SYgiRp8txfMruZuR2naGLmGxJKgmTpGX8lQV5qc1RdjY9FDnP
LsaojZkl4ux4XUoFodHlFsH/howSz+5SNTGJeGuE46BmwYISOhtkbcFTisERIe23
mhHV8AigOCx3PckwTg0nEV53FfqUGmOR39cM/YejoU3etGHqnuZkl2jCiExvXwL9
KfJgjm/z1sKR5e/z7etnbUVsL+IImhNIvwk7VGVIBfpOEk1t23MB19zi6CTYlMOY
gMCCE6p498gC349Uurpt4sHgTyFSv4Xv1uxjavSZp08gkpsxo3UMPs7j0rRijXFo
EntnjEci+SM3jfKNHR4tq7cCBUcPuXPJJx3UQ9uSbz67zOAIc7dsMiLZcPqLNdXM
DWbkaOqeC8IZ
=SFAU
-----END PGP SIGNATURE-----




Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Sun, 04 Jun 2017 07:29:20 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 17:14:46 2019; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.