MGASA-2017-0380

Source
https://advisories.mageia.org/MGASA-2017-0380.html
Import Source
https://advisories.mageia.org/MGASA-2017-0380.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2017-0380
Upstream
Published
2017-10-19T22:05:51Z
Modified
2026-04-16T06:24:15Z
Summary
Updated db48 and db53 packages fix security vulnerability
Details

It was found that Berkeley DB reads the DB_CONFIG configuration file from the current working directory by default. This happens when calling db_create() with dbenv=NULL; or using the dbm_open() function (CVE-2017-10140).

References
Credits

Affected packages

Mageia:5 / db48

Package

Name
db48
Purl
pkg:rpm/mageia/db48?arch=source&distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.8.30-18.1.mga5

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2017-0380.json"

Mageia:5 / db53

Package

Name
db53
Purl
pkg:rpm/mageia/db53?arch=source&distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
5.3.28-4.1.mga5

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2017-0380.json"

Mageia:6 / db48

Package

Name
db48
Purl
pkg:rpm/mageia/db48?arch=source&distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.8.30-21.1.mga6

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2017-0380.json"

Mageia:6 / db53

Package

Name
db53
Purl
pkg:rpm/mageia/db53?arch=source&distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
5.3.28-10.1.mga6

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2017-0380.json"