PT-2005-5575 · Gnome · Libgda2-Doc+11
Steve Kemp
·
Published
1970-01-01
·
Updated
2018-10-03
·
CVE-2005-2958
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
libgda versions prior to 1.2.2
libgda2 versions 1.2.1 and earlier
libgda2-3 versions prior to the fixed version
libgda2-dev versions prior to the fixed version
libgda2-doc versions prior to the fixed version
libgda2-3-dbg versions prior to the fixed version
libgda2-common versions prior to the fixed version
gda2-postgres versions prior to the fixed version
gda2-odbc versions prior to the fixed version
gda2-sqlite versions prior to the fixed version
gda2-freetds versions prior to the fixed version
gda2-mysql versions prior to the fixed version
Description
The issue concerns multiple vulnerabilities in the GNOME Data Access library, which can lead to a breach of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The vulnerabilities allow attackers to execute arbitrary code.
Recommendations
For libgda versions prior to 1.2.2, update to version 1.2.2 or later.
For libgda2 versions 1.2.1 and earlier, update to a version later than 1.2.1.
For libgda2-3, libgda2-dev, libgda2-doc, libgda2-3-dbg, libgda2-common, gda2-postgres, gda2-odbc, gda2-sqlite, gda2-freetds, gda2-mysql, update to the fixed version or apply the recommended patch.
As a temporary workaround, consider restricting access to the vulnerable components until a patch is available.
Avoid using the vulnerable library until the issue is resolved.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gda2-Freetds
Gda2-Mysql
Gda2-Odbc
Gda2-Postgres
Gda2-Sqlite
Libgda
Libgd2
Libgda2-3
Libgda2-3-Dbg
Libgda2-Common
Libgda2-Dev
Libgda2-Doc