CVE-2019-2708

Severity
3.3LOW
EPSS
0.9%
top 23.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 23
Latest updateMay 24

Description

Vulnerability in the Data Store component of Oracle Berkeley DB. Supported versions that are affected are Prior to 6.138, prior to 6.2.38 and prior to 18.1.32. Easily exploitable vulnerability allows low privileged attacker having Local Logon privilege with logon to the infrastructure where Data Store executes to compromise Data Store. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Data Store. CVSS 3.0 Base Score

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:LExploitability: 1.8 | Impact: 1.4

Affected Packages2 packages

NVDoracle/berkeley_db< 6.138
CVEListV5oracle_corporation/oracle_berkeley_dbunspecified6.138+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-4h5r-2hfh-8prm: Vulnerability in the Data Store component of Oracle Berkeley DB2022-05-24
CVEList
CVE-2019-2708: Vulnerability in the Data Store component of Oracle Berkeley DB2019-04-23

📋Vendor Advisories

2
Red Hat
libdb: Denial of service in the Data Store component2019-04-23
Microsoft
Vulnerability in the Data Store component of Oracle Berkeley DB. Supported versions that are affected are Prior to 6.138 prior to 6.2.38 and prior to 18.1.32. Easily exploitable vulnerability allows l2019-04-09

💬Community

4
Bugzilla
CVE-2019-2708 libdb: Denial of service in the Data Store component2020-07-02
Bugzilla
CVE-2019-2708 libdb4: libdb: data store execution leads to partial DoS [fedora-all]2020-07-02
Bugzilla
CVE-2019-2708 libdb4: libdb: data store execution leads to partial DoS [epel-7]2020-07-02
Bugzilla
CVE-2019-2708 libdb: data store execution leads to partial DoS [fedora-all]2020-07-02
CVE-2019-2708 (LOW CVSS 3.3) | Vulnerability in the Data Store com | cvebase.io