There are six critical, nine high, and two medium vulnerabilities
associated with ICU version 52.1 which can be found here:
https://nvd.nist.gov/vuln/search/results?form_type=Advanced&cves=on&cpe_version=cpe%3a%2fa%3aicu-project%3ainternational_components_for_unicode%3a52.1%3a%3a%7e%7e%7ec%252fc%252b%252b%7e%7e
Does anyone know if there are plans to address these?
Does anyone know what will be the impact of removing these files?
Thanks,
Mike Simmons
We are using Firebird 3.0.4 for our products. A client recently went through a security scan and identified a number of DLL's with security issues in Firebird.msvcp100.dll - support for this Visual C++ 2010 redistributable ended by Microsoft on 14 July 2020. Also there is one high risk vulnerability: https://nvd.nist.gov/vuln/detail/CVE-2010-3190 .
ZLib1.dll - This is version 1.2.8 (latest is 1.2.11). I have been unable to acquire 1.2.11. There are two critical and two high vulnerabilities associated with it: https://nvd.nist.gov/vuln/search/results?form_type=Advanced&cves=on&cpe_version=cpe%3a%2fa%3agnu%3azlib%3a1.2.8
icudt52.dll, icuin52.dll, icuuc52.dll:There are six critical, nine high, and two medium vulnerabilities associated with ICU version 52.1 which can be found here: https://nvd.nist.gov/vuln/search/results?form_type=Advanced&cves=on&cpe_version=cpe%3a%2fa%3aicu-project%3ainternational_components_for_unicode%3a52.1%3a%3a%7e%7e%7ec%252fc%252b%252b%7e%7e
--
You received this message because you are subscribed to the Google Groups "firebird-support" group.
To unsubscribe from this group and stop receiving emails from it, send an email to firebird-suppo...@googlegroups.com.
To view this discussion on the web, visit https://groups.google.com/d/msgid/firebird-support/9c1eec68-8ddc-4bdd-a51d-e1f532eb7889o%40googlegroups.com.
Hello,Is it zlib which uses MFC?
Hi Vlad,
I was attempting to find documentation of the gfix “-fix_icu” switch that you suggested could be used. For firebird 3.06 this isn’t listed as one of the valid switches shown when running gfix without any parameters. I couldn’t find this switch in the Firebird 4.0 Release Notes (but I did not try to run the 4.0 gfix to see if it is a valid switch).
Regards,
Mike Simmons
--
You received this message because you are subscribed to a topic in the Google Groups "firebird-support" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/firebird-support/h-Ild44X_XQ/unsubscribe.
To unsubscribe from this group and all its topics, send an email to firebird-suppo...@googlegroups.com.