MGASA-2017-0380

Source
https://advisories.mageia.org/MGASA-2017-0380.html
Import Source
https://advisories.mageia.org/MGASA-2017-0380.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2017-0380
Related
Published
2017-10-19T22:05:51Z
Modified
2017-10-19T21:41:25Z
Summary
Updated db48 and db53 packages fix security vulnerability
Details

It was found that Berkeley DB reads the DBCONFIG configuration file from the current working directory by default. This happens when calling dbcreate() with dbenv=NULL; or using the dbm_open() function (CVE-2017-10140).

References
Credits

Affected packages

Mageia:5 / db48

Package

Name
db48
Purl
pkg:rpm/mageia/db48?arch=source&distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.8.30-18.1.mga5

Ecosystem specific

{
    "section": "core"
}

Mageia:5 / db53

Package

Name
db53
Purl
pkg:rpm/mageia/db53?arch=source&distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.3.28-4.1.mga5

Ecosystem specific

{
    "section": "core"
}

Mageia:6 / db48

Package

Name
db48
Purl
pkg:rpm/mageia/db48?arch=source&distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.8.30-21.1.mga6

Ecosystem specific

{
    "section": "core"
}

Mageia:6 / db53

Package

Name
db53
Purl
pkg:rpm/mageia/db53?arch=source&distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.3.28-10.1.mga6

Ecosystem specific

{
    "section": "core"
}