Bug#842895: mariadb-10.0: CVE-2016-6664 CVE-2016-5617

2016-12-26 Thread Salvatore Bonaccorso
Control: retitle 842895 mariadb-10.0: CVE-2016-6664 Control: clone 842895 -1 Control: reassign -1 src:mariadb-10.1 Control: retitle -1 mariadb-10.1: CVE-2016-6664 Hi Otto, On Wed, Nov 02, 2016 at 07:27:40AM +0100, Salvatore Bonaccorso wrote: > Source: mariadb-10.0 > Version: 10.0.16-1 >

Bug#842895: mariadb-10.0: CVE-2016-6664 CVE-2016-5617

2016-12-18 Thread Otto Kekäläinen
Hello! CVE-2016-6664 (and duplicate CVE-2016-5617) do not gravely affect MariaDB because: "CVE-2016-6664 is NOT exploitable by itself. Shell access must first be obtained through a vulnerability like CVE-2016-6663. Because CVE-2016-6663 has been fixed and is no longer exploitable, we’ve

Bug#842895: mariadb-10.0: CVE-2016-6664 CVE-2016-5617

2016-11-02 Thread Salvatore Bonaccorso
Source: mariadb-10.0 Version: 10.0.16-1 Severity: grave Tags: security upstream Justification: user security hole Hi, the following vulnerabilities were published for mariadb-10.0. CVE-2016-6664[0], which is a duplicate of CVE-2016-5617. CVE-2016-5617[1]: | Unspecified vulnerability in Oracle