Red Hat Bugzilla – Bug 1548305
CVE-2018-7409 unixODBC: Buffer overflow in unicode_to_ansi_copy() can lead crash or other unspecified impact
Last modified: 2018-09-27 07:06:05 EDT
unixODBC before version 2.3.5 is vulnerable to a buffer overflow in the DriverManager/__info.c:unicode_to_ansi_copy() method. An attacker could exploit this to cause a denial of service or other unspecified impact. Upstream Release: https://sourceforge.net/projects/unixodbc/files/unixODBC/2.3.5/ Upstream Revision: https://sourceforge.net/p/unixodbc/code/136/#diff-12
Created unixODBC tracking bugs for this issue: Affects: fedora-all [bug 1548306]
When will you provide the fix for CVE-2018-7409 affected to package unixODBC Thanks and Regards, Vyshnav
Is unixODBC available on RHEL6.10 is vulnerable, as the patch is only available for 7.5