MySQL Forums
Forum List  »  Connector/ODBC

Re: CVE-2024-21262
Posted by: Jarod Burris
Date: October 22, 2024 12:56PM

Thank you for the confirmation. If you have any method of influence - if they would include the 32-bit driver version in the ("Supported Versions Affected") column it would relieve our need to ask this type of question. The tools used for scanning take the face value of what is published and scan against it - as the 32-bit driver isn't referenced we need to jump through hoops (such as this) to get sufficient documentation to identify alert validity.

https://www.oracle.com/security-alerts/cpuoct2024.html
CVE-2024-21262 - lists ("Supported Versions Affected") as ("9.0.0 and prior") which the scanner sees ("8.0.x") as a non-patched release... while other lines do reference the 32-bit release it doesn't seem to be applied for the ODBC driver.

Options: ReplyQuote


Subject
Written By
Posted
October 17, 2024 06:41PM
October 20, 2024 07:24PM
Re: CVE-2024-21262
October 22, 2024 12:56PM


Sorry, only registered users may post in this forum.

Content reproduced on this site is the property of the respective copyright holders. It is not reviewed in advance by Oracle and does not necessarily represent the opinion of Oracle or any other party.