Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Gregor Kopf of Secfault Security GmbH discovered that HSQLDB, a Java SQL database engine, allowed the execution of spurious scripting commands in .script and .log files. Hsqldb supports a "SCRIPT" keyword which is normally used to record the commands input by the database admin to output such a . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5995-1
Arbitrary File Write in hsqldb 1.8.0. (CVE-2023-1183) References: - https://bugs.mageia.org/show_bug.cgi?id=32042 - https://www.libreoffice.org/about-us/security/advisories/cve-2023-1183/ . MGASA-2023-0225 - Updated libreoffice packages fix security vulnerability Publication date: 07 Jul 2023 URL: https://advisories.mageia.org/MGASA-2023-0225.html Type: security Affected Mageia releases: 8 CVE: CVE-2023-1183 Arbitrary File Write in hsqldb 1.8.0. (CVE-2023-1183) References: - https://bugs.mageia.org/show_bug.cgi?id=32042 - https://www.libreoffice.org/about-us/security/advisories/cve-2023-1183/ - https://www.cve.org/CVERecord?id=CVE-2023-1183 SRPMS: - 8/core/libreoffice-7.4.5.1-1.2.mga8 . The recent updates to LibreOffice packages rectify a critical arbitrary file write vulnerability in Mageia 8. This advisory is listed as MGASA-2023-0225.. Mageia Security Advisory, LibreOffice Update, HSQLDB Issue, Arbitrary Write Vulnerability. . Severity: Critical. LinuxSecurity.com Team
Gregor Kopf of Secfault Security GmbH discovered that HSQLDB, a Java SQL database engine, allowed the execution of spurious scripting commands in .script and .log files. Hsqldb supports a "SCRIPT" keyword which is normally used to record the commands input by the database admin to output . -------------------------------------------------------------------------Debian LTS Advisory DLA-3468-1
Gregor Kopf of Secfault Security GmbH discovered that HSQLDB, a Java SQL database engine, allowed the execution of spurious scripting commands in .script and .log files. Hsqldb supports a "SCRIPT" keyword which is normally used to record the commands input by the database admin to output . -------------------------------------------------------------------------Debian LTS Advisory DLA-3467-1
Gregor Kopf of Secfault Security GmbH discovered that HSQLDB, a Java SQL database engine, allowed the execution of spurious scripting commands in .script and .log files. Hsqldb supports a "SCRIPT" keyword which is normally used to record the commands input by the database admin to output such a . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5436-1
The following updated rpms for Oracle Linux 6 Extended Lifecycle Support (ELS) have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-12103 https://linux.oracle.com/errata/ELSA-2023-12103.html The following updated rpms for Oracle Linux 6 Extended Lifecycle Support (ELS) have been uploaded to the Unbreakable Linux Network: hsqldb-1.8.0.10-12.0.1.el6.noarch.rpm hsqldb-demo-1.8.0.10-12.0.1.el6.noarch.rpm hsqldb-javadoc-1.8.0.10-12.0.1.el6.noarch.rpm hsqldb-manual-1.8.0.10-12.0.1.el6.noarch.rpm x86_64: hsqldb-1.8.0.10-12.0.1.el6.noarch.rpm hsqldb-demo-1.8.0.10-12.0.1.el6.noarch.rpm hsqldb-javadoc-1.8.0.10-12.0.1.el6.noarch.rpm hsqldb-manual-1.8.0.10-12.0.1.el6.noarch.rpm Related CVEs: CVE-2022-41853 Description of changes: [1:1.8.0.10-12.0.1] - Fix possible remote code execution vulnerability [CVE-2022-41853][Orabug: 34820687] _______________________________________________ El-errata mailing list
It was found that those using java.sql.Statement or java.sql.PreparedStatement in hsqldb, a Java SQL database, to process untrusted input may be vulnerable to a remote code execution attack. By default it is allowed to call any static method of any Java class in the classpath resulting in code execution. The . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5313-1
It was found that those using java.sql.Statement or java.sql.PreparedStatement in hsqldb, a Java SQL database, to process untrusted input may be vulnerable to a remote code execution attack. By default it is allowed to call any static method of any Java class in the classpath resulting in code execution. The . -------------------------------------------------------------------------Debian LTS Advisory DLA-3234-1
Get the latest Linux and open source security news straight to your inbox.