﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
6472	mariadb-10.0.18	Fernando de Oliveira	Fernando de Oliveira	"[https://downloads.mariadb.org/interstitial/mariadb-10.0.18/source/mariadb-10.0.18.tar.gz]

md5sum: eab4f9303883d33558c0059af9e30aa4

[https://mariadb.com/kb/en/mariadb/mariadb-10018-release-notes/]

{{{
...

Security Fixes

    Fixes for the following security vulnerabilities:
    (They can be found at https://cve.mitre.org)

        CVE-2014-8964 bundled PCRE contained heap-based buffer overflow
        vulnerability that allowed the server to crash or have other
        unspecified impact via a crafted regular expression made possible with
        the REGEXP_SUBSTR function (MDEV-8006).

        CVE-2015-0501: Unspecified vulnerability in Oracle MySQL Server 5.5.42
        and earlier, and 5.6.23 and earlier, allows remote authenticated users
        to affect availability via unknown vectors related to Server :
        Compiling.

        CVE-2015-2571: Unspecified vulnerability in Oracle MySQL Server 5.5.42
        and earlier, and 5.6.23 and earlier, allows remote authenticated users
        to affect availability via unknown vectors related to Server :
        Optimizer.

        CVE-2015-0505: Unspecified vulnerability in Oracle MySQL Server 5.5.42
        and earlier, and 5.6.23 and earlier, allows remote authenticated users
        to affect availability via vectors related to DDL.

        CVE-2015-0499: Unspecified vulnerability in Oracle MySQL Server 5.5.42
        and earlier, and 5.6.23 and earlier, allows remote authenticated users
        to affect availability via unknown vectors related to Server :
        Federated. 

...
}}}"	enhancement	closed	high	7.8	BOOK	SVN	medium	fixed		
