[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Query on db package security vurnerablity



Hi ,

Can you guys tell why the below listed cves mentioned as NOT-FOR-US in debian security tracker?. Is it possible to provide fix for this?

CVE-2017-3617
CVE-2017-3612
CVE-2017-3606
CVE-2017-3613
CVE-2017-3615
CVE-2017-3616
CVE-2017-3605
CVE-2017-3611
CVE-2017-3604
CVE-2017-3614
CVE-2017-3610
CVE-2017-3607
CVE-2017-3609
CVE-2017-3608 

Example:

NameCVE-2017-3609
DescriptionVulnerability in the Data Store component of Oracle Berkeley DB. The supported version that is affected is Prior to 6.2.32. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Data Store executes to compromise Data Store. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Data Store. CVSS 3.0 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).
SourceCVE (at NVDCERTLWNoss-secfulldiscbugtraqEDBMetasploitRed HatUbuntuGentoo, SUSE bugzilla/CVEMageia, GitHub code/issuesweb searchmore)
NVD severitylow (attack range: local)

Notes

NOT-FOR-US: Oracle

Reference: 
https://www.oracle.com/technetwork/security-advisory/cpuapr2017verbose-3236619.html

--
Sathish Nagaiyan
Timesys Corporation

Reply to: