Re: BerkeleyDB CVEs
Jeremy Stanley <[email protected]> Fri, 26 Sep 2025 14:45:17 +0000
| Newsgroups | gmane.linux.debian.devel.security |
|---|---|
| Message-ID | <[email protected]> |
--tAKMI2NHraJlO/Qk Content-Type: text/plain; charset=utf-8; format=flowed Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On 2025-09-26 12:43:43 +0000 (+0000), Tom=C3=A1=C5=A1 Mac=C3=A1k wrote: [...] > They came up with list of high criticality CVEs from Oracle=20 > Berkeley DB libdb5.3 package, which on your tracker list are=20 > marked as =E2=80=9CNOT-FOR-US: Oracle=E2=80=9D. They argue that package= =20 > libdb5.3/5.3.28 is installed which is affected accrding to Oracle=20 > (https://www.oracle.com/security-alerts/cpuapr2017.html#AppendixTOOL)=20 > thus we=E2=80=99re vulnerable [...] Spot checking a bunch of the ones you listed in Debian's security=20 tracker, it looks like they're either flagged as specific to=20 Oracle's closed source Berkeley DB product: https://security-tracker.debian.org/tracker/CVE-2016-0689 =2E..or Oracle did not supply sufficient public information for anyone=20 to be able to identify what the fix was so that it could be=20 confirmed as affecting Debian much less backported: https://security-tracker.debian.org/tracker/CVE-2015-2624 My perspective as both an upstream free/libre open source software=20 project vulnerability manager as well as a sysadmin responsible for=20 securing a vast number of Internet-connected systems is that=20 BlackDuck's scanner isn't all that useful due to woefully=20 insufficient report context, its inability to identify backported=20 fixes in distributions, and the *terrible* misconception that the=20 existence of a CVE necessarily implies an actual security risk (I've=20 given up disputing the endless flood of useless CVEs I see reported=20 any more). And Oracle's not helping matters, they're notorious since decades=20 for being intentionally tight-lipped about any security issues they=20 fix in their products. The other thing to pay attention to is that db5.3 is orphaned and=20 newer versions aren't suitably licensed for main, so BDB has no real=20 future in Debian: https://bugs.debian.org/1055356 In short, I don't think you're going to get any satisfactory answer=20 to your question because the situation itself is unsatisfactory. --=20 Jeremy Stanley --tAKMI2NHraJlO/Qk Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQKTBAABCgB9FiEEl65Jb8At7J/DU7LnSPmWEUNJWCkFAmjWpvdfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDk3 QUU0OTZGQzAyREVDOUZDMzUzQjJFNzQ4Rjk5NjExNDM0OTU4MjkACgkQSPmWEUNJ WCmU8xAAnNm3do5w9Fgf06y1KYYrf4jEWTocNYC97Ne0SkNZCNKQ9E4YdZGtIdcs 1V01/2E+9yLzx9GHckDlnuGgZmvCTZwhxgWwAsR8JY3XQ6f6A5BKvcYyhrbgqPOT Aoh6ciEe553LpR3SPeBlTfiwp3PbWIvpfxcsalPg8HWif8smLGC3v5K3Xjl3eEYq FdoXXRvi647NKK6ZKep9sR8BIDXVUSccMI9O8KNTAseYx1QJ/LEMwj/xHs6p+Vcz 5JV7Z2r+F89zky8E6w6r6svLx4L6vKo+B3u4HEOEO4PmjeMsXNBfNtIMonNRhUum I2PCvqDeBzqyWUTj3T9LnkT1qpAtd69RVPEHapF/mjPj/LEMFQApyxE4CYx3K+T6 aPZY+a+bbMq/hU2lwa+7HNYRi+KfEFVI3GmGpWrC74/wiyaH7dQtAZq1EGAEz1b6 lA5XHKKoyBOGRmCb69HhYPcS9MDXA+4DK4eLxHh1ydiizp9UDWDAct7WUhhVCBrb R9kzAsYhw2+CSGOBM7KILsxyTCumqA1k3QknDgKLwL8KhhCfdoNkl1QI1BwDcMi4 aGePQ/62cil73O/ku9XqsnwBRfCaswii8ARY0H5T3LXiCrZIcXNOBhh/8ZQtH8VT QHGDH3JFBCu64JdnJaLv0iSCHq+ua0W3HGQPEo6vL4jj9tlqpFw= =MI1n -----END PGP SIGNATURE----- --tAKMI2NHraJlO/Qk--