Path to this page:
Subject: CVS commit: pkgsrc/databases
From: Adam Ciarcinski
Date: 2016-10-14 21:28:29
Message id: 20161014192829.2568BFBD2@cvs.NetBSD.org
Log Message:
Changes 5.7.16:
Security Notes
--------------
* Incompatible Change: For STANDALONE and WIN builds, the default \
secure_file_priv value has changed from the empty string to NULL. This is a \
secure-by-default setting because it disables import and export operations. To \
permit those operations, set secure_file_priv to the path name of the directory \
to use for those operations.
* The linked OpenSSL library for the MySQL Commercial Server has been updated to \
version 1.0.1u. For a description of issues fixed in this version, see \
http://www.openssl.org/news/vulnerabilities.html.
This change does not affect the Oracle-produced MySQL Community build of MySQL \
Server, which uses the yaSSL library instead.
Functionality Added or Changed
------------------------------
* yaSSL was upgraded to version 2.4.2. This upgrade corrects issues with: \
Potential AES side channel leaks; DSA padding for unusual sizes; the \
SSL_CTX_load_verify_locations() OpenSSL compatibility function failing to handle \
long path directory names.
Files: