MGASA-2018-0379
Dashboard / Vulnerabilities / MGASA-2018-0379
MGASA-2018-0379
Summary: Updated unixODBC packages fix security vulnerability
Details: unixODBC before version 2.3.5 is vulnerable to a buffer overflow in the DriverManager/__info.c:unicode_to_ansi_copy() method. An attacker could exploit this to cause a denial of service or other unspecified impact (CVE-2018-7409). The SQLWriteFileDSN function in odbcinst/SQLWriteFileDSN.c in unixODBC 2.3.5 has strncpy arguments in the wrong order, which allows attackers to cause a denial of service or possibly have unspecified other impact (CVE-2018-7485).
References: https://advisories.mageia.org/MGASA-2018-0379.html, https://bugs.mageia.org/show_bug.cgi?id=23253, https://lists.fedoraproject.org/archives/list/[email protected]/thread/FNQ5MBIGSDZTV3C7TRG7BMA6GMVJVOYO/
Affected packages
Package
Name: unixODBC
Purl: pkg:rpm/mageia/unixODBC?arch=source&distro=mageia-6
Affected ranges
Type: ECOSYSTEM
Events:
