From Mageia wiki
Jump to: navigation, search

MGASA-2013-0046

Date: February 9th, 2013
Affected releases: 2
Media: Core


Description:
Updated mariadb packages includes fixes for the following security
vulnerabilities:

A buffer overflow that can cause a server crash or arbitrary code
execution (a variant of CVE-2012-5611)

fast password brute-forcing using the "change user" command
(CVE-2012-5627/MDEV-3915)

information leakage about existing user accounts via the protocol
handshake (CVE-2012-5615/MDEV-3909)

Be advised that for CVE-2012-5615 to be completely closed, it's
recommended to remove any anonymous logins. Previously, such a
user without access rights was added by default.

in addition it fixes MDEV-4029 and rpl.rpl_mdev382 test from
mariadb-bench


Updated Packages:
i586:
libmariadb-devel-5.5.25-2.8.mga2.i586.rpm
libmariadb-embedded18-5.5.25-2.8.mga2.i586.rpm
libmariadb-embedded-devel-5.5.25-2.8.mga2.i586.rpm
mariadb-5.5.25-2.8.mga2.i586.rpm
mariadb-bench-5.5.25-2.8.mga2.i586.rpm
mariadb-client-5.5.25-2.8.mga2.i586.rpm
mariadb-common-5.5.25-2.8.mga2.i586.rpm
mariadb-common-core-5.5.25-2.8.mga2.i586.rpm
mariadb-core-5.5.25-2.8.mga2.i586.rpm
mariadb-extra-5.5.25-2.8.mga2.i586.rpm
mariadb-feedback-5.5.25-2.8.mga2.i586.rpm
mariadb-obsolete-5.5.25-2.8.mga2.i586.rpm
mysql-MariaDB-5.5.25-2.8.mga2.i586.rpm
mariadb-debug-5.5.25-2.8.mga2.i586.rpm

x86_64:
lib64mariadb18-5.5.25-2.8.mga2.x86_64.rpm
lib64mariadb-devel-5.5.25-2.8.mga2.x86_64.rpm
lib64mariadb-embedded18-5.5.25-2.8.mga2.x86_64.rpm
lib64mariadb-embedded-devel-5.5.25-2.8.mga2.x86_64.rpm
mariadb-5.5.25-2.8.mga2.x86_64.rpm
mariadb-bench-5.5.25-2.8.mga2.x86_64.rpm
mariadb-client-5.5.25-2.8.mga2.x86_64.rpm
mariadb-common-5.5.25-2.8.mga2.x86_64.rpm
mariadb-common-core-5.5.25-2.8.mga2.x86_64.rpm
mariadb-core-5.5.25-2.8.mga2.x86_64.rpm
mariadb-extra-5.5.25-2.8.mga2.x86_64.rpm
mariadb-feedback-5.5.25-2.8.mga2.x86_64.rpm
mariadb-obsolete-5.5.25-2.8.mga2.x86_64.rpm
mysql-MariaDB-5.5.25-2.8.mga2.x86_64.rpm
mariadb-debug-5.5.25-2.8.mga2.x86_64.rpm

SRPMS:
mariadb-5.5.25-2.8.mga2.src.rpm


References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5611
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5615
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5627
https://mariadb.atlassian.net/browse/MDEV-4029
https://mariadb.atlassian.net/browse/MDEV-3915
https://mariadb.atlassian.net/browse/MDEV-3909
https://bugs.mageia.org/show_bug.cgi?id=8921