ALAS2-2023-1965

Related Vulnerabilities: CVE-2017-10140  

Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented functionality in Berkeley DB 2.x and later, related to reading settings from DB_CONFIG in the current directory. (CVE-2017-10140)

ALAS2-2023-1965


Amazon Linux 2 Security Advisory: ALAS-2023-1965
Advisory Release Date: 2023-03-02 21:49 Pacific
Advisory Updated Date: 2023-03-07 00:19 Pacific
Severity: Important

Issue Overview:

Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented functionality in Berkeley DB 2.x and later, related to reading settings from DB_CONFIG in the current directory. (CVE-2017-10140)


Affected Packages:

libdb


Issue Correction:
Run yum update libdb to update your system.

New Packages:
aarch64:
    libdb-5.3.21-24.amzn2.0.4.aarch64
    libdb-utils-5.3.21-24.amzn2.0.4.aarch64
    libdb-devel-5.3.21-24.amzn2.0.4.aarch64
    libdb-devel-static-5.3.21-24.amzn2.0.4.aarch64
    libdb-cxx-5.3.21-24.amzn2.0.4.aarch64
    libdb-cxx-devel-5.3.21-24.amzn2.0.4.aarch64
    libdb-tcl-5.3.21-24.amzn2.0.4.aarch64
    libdb-tcl-devel-5.3.21-24.amzn2.0.4.aarch64
    libdb-sql-5.3.21-24.amzn2.0.4.aarch64
    libdb-sql-devel-5.3.21-24.amzn2.0.4.aarch64
    libdb-java-5.3.21-24.amzn2.0.4.aarch64
    libdb-java-devel-5.3.21-24.amzn2.0.4.aarch64
    libdb-debuginfo-5.3.21-24.amzn2.0.4.aarch64

i686:
    libdb-5.3.21-24.amzn2.0.4.i686
    libdb-utils-5.3.21-24.amzn2.0.4.i686
    libdb-devel-5.3.21-24.amzn2.0.4.i686
    libdb-devel-static-5.3.21-24.amzn2.0.4.i686
    libdb-cxx-5.3.21-24.amzn2.0.4.i686
    libdb-cxx-devel-5.3.21-24.amzn2.0.4.i686
    libdb-tcl-5.3.21-24.amzn2.0.4.i686
    libdb-tcl-devel-5.3.21-24.amzn2.0.4.i686
    libdb-sql-5.3.21-24.amzn2.0.4.i686
    libdb-sql-devel-5.3.21-24.amzn2.0.4.i686
    libdb-java-5.3.21-24.amzn2.0.4.i686
    libdb-java-devel-5.3.21-24.amzn2.0.4.i686
    libdb-debuginfo-5.3.21-24.amzn2.0.4.i686

noarch:
    libdb-devel-doc-5.3.21-24.amzn2.0.4.noarch

src:
    libdb-5.3.21-24.amzn2.0.4.src

x86_64:
    libdb-5.3.21-24.amzn2.0.4.x86_64
    libdb-utils-5.3.21-24.amzn2.0.4.x86_64
    libdb-devel-5.3.21-24.amzn2.0.4.x86_64
    libdb-devel-static-5.3.21-24.amzn2.0.4.x86_64
    libdb-cxx-5.3.21-24.amzn2.0.4.x86_64
    libdb-cxx-devel-5.3.21-24.amzn2.0.4.x86_64
    libdb-tcl-5.3.21-24.amzn2.0.4.x86_64
    libdb-tcl-devel-5.3.21-24.amzn2.0.4.x86_64
    libdb-sql-5.3.21-24.amzn2.0.4.x86_64
    libdb-sql-devel-5.3.21-24.amzn2.0.4.x86_64
    libdb-java-5.3.21-24.amzn2.0.4.x86_64
    libdb-java-devel-5.3.21-24.amzn2.0.4.x86_64
    libdb-debuginfo-5.3.21-24.amzn2.0.4.x86_64