← Back to team overview

maria-developers team mailing list archive

Re: Several CVE's in Oracle MySQL, is MariaDB vulnerable?

 

On Fri, Oct 23, 2015 at 10:15:13PM +0200, Sergei Golubchik wrote:
> I've just found out. It turned out that we're run out of accounts (our
> Jira license has a limit on that). I've deactivated accounts that were
> created during our launchpad->jira migration (they weren't real users
> anyway), so registration should work again for a while.
> 
> Meanwhile we'll fix the license.

Yep I can confirm this problem. That was the problem that stops me setting up a
bugreport/issue request.
> 
> > > I am from the Archlinux-Security Team and want to ask if mariadb in the actual
> > > version is vulnerable to the following CVEs:
> > > 
> > > CVE-2015-4913 CVE-2015-4910 CVE-2015-4905 CVE-2015-4904 CVE-2015-4895
> > > CVE-2015-4890 CVE-2015-4879 CVE-2015-4870 CVE-2015-4862 CVE-2015-4864
> > > CVE-2015-4861 CVE-2015-4858 CVE-2015-4836 CVE-2015-4833 CVE-2015-4830
> > > CVE-2015-4826 CVE-2015-4819 CVE-2015-4815 CVE-2015-4807 CVE-2015-4802
> > > CVE-2015-4800 CVE-2015-4792 CVE-2015-4791 CVE-2015-4766
> > > 
> > > I hope you can help me.
> > 
> > Of course, listed here:
> > 
> > https://mariadb.com/kb/en/mariadb/security/
> 

Thx for your List :-)

Nice work with mariadb guys!
Thats all from me.

--------------------------------------------------------------
Christian Rebischke
Member of Archlinux CVE-Monitoring Team

Website    : www.nullday.de
Twitter    : @sh1bumi
Jabber     : shibumi@xxxxxxxxxxxxx
PGP        : 0xDFE2060D
Fingerprint: 6DAF 7B80 8F9D F251 3962 0000 D214 61E3 DFE2 060D
--------------------------------------------------------------

Attachment: signature.asc
Description: PGP signature


References