[debian-mysql] Bug#885345: mariadb-10.1: CVE-2017-15365: Replication in sql/event_data_objects.cc occurs before ACL checks

Salvatore Bonaccorso carnil at debian.org
Tue Dec 26 14:15:35 UTC 2017


Source: mariadb-10.1
Version: 1:10.1.29-6
Severity: important
Tags: security upstream fixed-upstream
Control: found -1 10.1.23-1


Hi,

the following vulnerability was published for mariadb-10.1, this is
fixed in 10.1.30.

CVE-2017-15365[0]:
Replication in sql/event_data_objects.cc occurs before ACL checks

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2017-15365
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15365
[1] https://bugzilla.redhat.com/show_bug.cgi?id=1524234

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore



More information about the pkg-mysql-maint mailing list