{
  "schema_version": "1.7.0",
  "id": "MGASA-2021-0057",
  "published": "2021-01-29T19:05:33Z",
  "modified": "2021-01-29T18:24:20Z",
  "summary": "Updated db53 packages fix a security vulnerability",
  "details": "Vulnerability in the Data Store component of Oracle Berkeley DB. Easily\nexploitable vulnerability allows low privileged attacker having Local Logon\nprivilege with logon to the infrastructure where Data Store executes to\ncompromise Data Store. Successful attacks of this vulnerability can result in\nunauthorized ability to cause a partial denial of service (partial DOS) of Data\nStore (CVE-2019-2708).\n",
  "upstream": [
    "CVE-2019-2708"
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://advisories.mageia.org/MGASA-2021-0057.html"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.mageia.org/show_bug.cgi?id=27960"
    },
    {
      "type": "ADVISORY",
      "url": "http://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html"
    },
    {
      "type": "WEB",
      "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/OQFKX6NKU2DCW5CTCHQSOJJDFVRVTPO6/"
    }
  ],
  "affected": [
    {
      "package": {
        "ecosystem": "Mageia:7",
        "name": "db53",
        "purl": "pkg:rpm/mageia/db53?arch=source&distro=mageia-7"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "5.3.28-17.1.mga7"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    }
  ],
  "credits": [
    {
      "name": "Mageia",
      "type": "COORDINATOR",
      "contact": [
        "https://wiki.mageia.org/en/Packages_Security_Team"
      ]
    }
  ]
}
