Summary: | <dev-db/mysql-workbench-8.0.27: vulnerabilities in bundled sqlite and openssl (CVE-2021-{20227,3712}) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | John Helmert III <ajak> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED INVALID | ||
Severity: | minor | CC: | graaff |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | B4 [stable?] | ||
Package list: | Runtime testing required: | --- |
Description
John Helmert III
![]() ![]() ![]() ![]() (In reply to John Helmert III from comment #0) > These don't seem to be unbundled, so I assume we're vulnerable? If so, need > to stabilize .27. My understanding is that these are only bundled on platforms that cannot easily provide them natively, e.g. windows. The community src version that we use does not bundle openssl as far as I can tell and uses normal cmake rules to find it in the system. sqlite is used indirectly through vsqlite++ which dynamically links to sqlite. (In reply to Hans de Graaff from comment #1) > (In reply to John Helmert III from comment #0) > > > These don't seem to be unbundled, so I assume we're vulnerable? If so, need > > to stabilize .27. > > My understanding is that these are only bundled on platforms that cannot > easily provide them natively, e.g. windows. Got it! > The community src version that we use does not bundle openssl as far as I > can tell and uses normal cmake rules to find it in the system. I guess the ebuilds should have such a dependency, then? > sqlite is used indirectly through vsqlite++ which dynamically links to > sqlite. Ok, nothing for us to do here |