Name
db
Version
5.3.28-r
Type
library
Description
-
Licenses
-
PURL
-
CPE
-

Other Versions#


Project
Branch
Version
openwrt-25.12
5.3.28-r2

Patches#


#
Title
Author
Resolve
1
Fix libc++ compatibility by renaming atomic_init API
Khem Raj <raj.khem@gmail.com>
2
Patch #2
Unknown
CVE-2017-10140
3
Patch #3
Martin Jansa <Martin.Jansa@gmail.com>
4
Patch #4
Unknown
5
Patch #5
Unknown
CVE-2019-2708
6
Patch #6
Unknown
7
Patch #7
Unknown
CVE-2019-8457
8
clock: Do not define own timespec
Khem Raj <raj.khem@gmail.com>
9
Patch #9
Unknown
10
atomic: Rename local __atomic_compare_exchange to avoid clash
Khem Raj <raj.khem@gmail.com>
11
Patch #11
Unknown
12
Patch #12
Ross Burton <ross.burton@intel.com>
13
MMAP_EXTEND mode requires we extend in full system page increments
Andy Whitcroft <apw@canonical.com>
14
Patch #14
Unknown
15
configure: Add explicit tag options to libtool invocation
Khem Raj <raj.khem@gmail.com>
16
Patch #16
Unknown

Vulnerabilities#


Name
Analysis
Description
Patched
SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree tables.
Patched
Vulnerability in the Data Store component of Oracle Berkeley DB. Supported versions that are affected are Prior to 6.138, prior to 6.2.38 and prior to 18.1.32. Easily exploitable vulnerability allows low privileged attacker having Local Logon privilege with logon to the infrastructure where Data Store executes to compromise Data Store. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Data Store. CVSS 3.0 Base Score 3.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).
Patched
Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented functionality in Berkeley DB 2.x and later, related to reading settings from DB_CONFIG in the current directory.