Bug 29678 - firebird new security issue CVE-2017-11509
Summary: firebird new security issue CVE-2017-11509
Status: RESOLVED DUPLICATE of bug 26288
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: Mageia Bug Squad
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2021-11-20 17:51 CET by David Walser
Modified: 2021-11-23 14:22 CET (History)
2 users (show)

See Also:
Source RPM: firebird-3.0.7.33374-1.mga8.src.rpm
CVE:
Status comment: no fixes upstream, just mitigation


Attachments

Description David Walser 2021-11-20 17:51:17 CET
Debian-LTS has issued an advisory today (November 20):
https://www.debian.org/lts/security/2021/dla-2824

I'm not sure if Cauldron (firebird 4.0.x) is affected.
Nicolas Lécureuil 2021-11-22 22:06:30 CET

CC: (none) => mageia
Status comment: (none) => no fixes upstream, just mitigation

Comment 1 Philippe Makowski 2021-11-23 14:22:04 CET
and for cauldron :
UDFs are deprecated in v.4. That means that UDFs can’t be used with default configuration (parameter “UdfAccess” set to “None”) and all sample UDF libraries (ib_udf, fbudf) are not distributed any more.

*** This bug has been marked as a duplicate of bug 26288 ***

Status: NEW => RESOLVED
Resolution: (none) => DUPLICATE
CC: (none) => makowski.mageia


Note You need to log in before you can comment on or make changes to this bug.