Incorrect default permissions in Oracle Berkeley DB - CVE-2019-2708

 

Incorrect default permissions in Oracle Berkeley DB - CVE-2019-2708

Published: June 23, 2021


Vulnerability identifier: #VU54338
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-2708
CWE-ID: CWE-276
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to crash the service.

The vulnerability exists due to incorrect default permissions for files and folders that are set by the application. A local user with access to the system can cause a denial of service attack.


Affected software

Oracle Berkeley DB
Dell Data Protection Central
Dell EMC PowerProtect Data Protection
Red Hat OpenShift Serverless
Windows Container Support for Red Hat OpenShift
OpenShift Virtualization
Cloud Pak for Security (CP4S)
Red Hat OpenShift Jaeger
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
openSUSE Leap Micro
SUSE Enterprise Storage
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
openSUSE Leap
openEuler
Fedora
Web Terminal
Dell EMC NetWorker vProxy
libdb-4_8-debuginfo
libdb-4_8-debuginfo-32bit
libdb-4_8-32bit
libdb-4_8
db48-utils
libdb-4_8-devel
libdb-4_8-debugsource
libdb-4_8-32bit-debuginfo
db48-utils-debuginfo
libdb_java-4_8-debuginfo
libdb_java-4_8-debugsource
libdb_java-4_8-devel
db48-doc
libdb_java-4_8
libdb-4_8-devel-32bit
libdb
libdb-help
libdb-debugsource
libdb-debuginfo
libdb-devel
libdb (Red Hat package)
EMC ViPR SRM
Dell EMC Storage Monitoring and Reporting (SMR)
RecoverPoint for VMs

How to mitigate CVE-2019-2708

Install updates from vendor's website.

Oracle Berkeley DB - addressed in versions 6.1.38, 6.2.38, 18.1.32
Red Hat OpenShift Serverless - update to 1.16.0
Cloud Pak for Security (CP4S) - update to 1.8.0.0
Red Hat OpenShift Jaeger - addressed in versions 1.17.9, 1.20.4
Windows Container Support for Red Hat OpenShift - update to 2.0.1
Web Terminal - update to 1.3
OpenShift Virtualization - addressed in versions 2.6.6, 4.8.0
Dell EMC NetWorker vProxy - update to 4.3.0-40
libdb-4_8-debuginfo - addressed in versions 4.8.30-33.1, 4.8.30-150000.7.6.1
libdb-4_8-debuginfo-32bit - update to 4.8.30-33.1
libdb-4_8-32bit - addressed in versions 4.8.30-33.1, 4.8.30-150000.7.6.1
libdb-4_8 - addressed in versions 4.8.30-33.1, 4.8.30-150000.7.6.1
db48-utils - addressed in versions 4.8.30-33.1, 4.8.30-150000.7.6.1
libdb-4_8-devel - addressed in versions 4.8.30-33.1, 4.8.30-150000.7.6.1
libdb-4_8-debugsource - addressed in versions 4.8.30-33.1, 4.8.30-150000.7.6.1
libdb-4_8-32bit-debuginfo - update to 4.8.30-150000.7.6.1
db48-utils-debuginfo - update to 4.8.30-150000.7.6.1
libdb_java-4_8-debuginfo - update to 4.8.30-150000.7.6.1
libdb_java-4_8-debugsource - update to 4.8.30-150000.7.6.1
libdb_java-4_8-devel - update to 4.8.30-150000.7.6.1
db48-doc - update to 4.8.30-150000.7.6.1
libdb_java-4_8 - update to 4.8.30-150000.7.6.1
libdb-4_8-devel-32bit - update to 4.8.30-150000.7.6.1
EMC ViPR SRM - update to 4.9.0.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.9.0.0
libdb - update to 5.3.28-36
libdb-help - update to 5.3.28-36
libdb-debugsource - update to 5.3.28-36
libdb-debuginfo - update to 5.3.28-36
libdb-devel - update to 5.3.28-36
libdb (Red Hat package) - update to 5.3.28-40.el8
libdb - update to 5.3.28-45.fc33
RecoverPoint for VMs - update to 6.0.SP1.P1

External References

Related Security Bulletins