Hi ,

Can you guys tell why the below listed cves mentioned as NOT-FOR-US in
debian security tracker?. Is it possible to provide fix for this?

CVE-2017-3617
CVE-2017-3612
CVE-2017-3606
CVE-2017-3613
CVE-2017-3615
CVE-2017-3616
CVE-2017-3605
CVE-2017-3611
CVE-2017-3604
CVE-2017-3614
CVE-2017-3610
CVE-2017-3607
CVE-2017-3609
CVE-2017-3608
Example:

*Name* CVE-2017-3609
*Description* Vulnerability in the Data Store component of Oracle Berkeley
DB. The supported version that is affected is Prior to 6.2.32. Difficult to
exploit vulnerability allows unauthenticated attacker with logon to the
infrastructure where Data Store executes to compromise Data Store.
Successful attacks require human interaction from a person other than the
attacker. Successful attacks of this vulnerability can result in takeover
of Data Store. CVSS 3.0 Base Score 7.0 (Confidentiality, Integrity and
Availability impacts). CVSS Vector:
(CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).
*Source* CVE <https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3609>
 (at NVD <https://nvd.nist.gov/vuln/detail/CVE-2017-3609>; CERT
<https://www.kb.cert.org/vuls/byid?query=CVE-2017-3609&searchview=>, LWN
<https://lwn.net/Search/DoSearch?words=CVE-2017-3609>, oss-sec
<https://marc.info/?s=CVE-2017-3609&l=oss-security>, fulldisc
<https://marc.info/?s=CVE-2017-3609&l=full-disclosure>, bugtraq
<https://marc.info/?s=CVE-2017-3609&l=bugtraq>, EDB
<https://www.exploit-db.com/search/?action=search&cve=2017-3609>, Metasploit
<https://www.rapid7.com/db/search?q=CVE-2017-3609>, Red Hat
<https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-3609>, Ubuntu
<https://people.canonical.com/~ubuntu-security/cve/CVE-2017-3609>, Gentoo
<https://bugs.gentoo.org/show_bug.cgi?id=CVE-2017-3609>, SUSE bugzilla
<https://bugzilla.novell.com/show_bug.cgi?id=CVE-2017-3609>/CVE
<https://www.suse.com/security/cve/CVE-2017-3609/>, Mageia
<https://advisories.mageia.org/CVE-2017-3609.html>, GitHub code
<https://github.com/search?q=%22CVE-2017-3609%22&type=Code>/issues
<https://github.com/search?q=%22CVE-2017-3609%22&type=Issues>, web search
<https://duckduckgo.com/html?q=%22CVE-2017-3609%22>, more
<http://oss-security.openwall.org/wiki/vendors>)
*NVD severity* low (attack range: local)Notes

NOT-FOR-US: Oracle


Reference:

https://www.oracle.com/technetwork/security-advisory/cpuapr2017verbose-3236619.html

-- 
Sathish Nagaiyan
Timesys Corporation

Reply via email to