CVE-2019-16168
medium
CVSS v3
6.5
CVSS v4 NEW
โ
VIR risk
6.5
Description
RHSA-2021:1968: mingw packages security and bug fix update (Moderate)
Predictions
Exploit likelihood
75%
Patch ETA
โ
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
OS impact
Fedora Affected 1 release
| Version | Status | Fixed in |
|---|---|---|
| 30 | Affected | โ |
SUSE Affected 1 release
| Version | Status | Fixed in |
|---|---|---|
| โ | Affected | โ |
Ubuntu Affected 5 releases
| Version | Status | Fixed in |
|---|---|---|
| 19.10 | Affected | โ |
| 19.04 | Affected | โ |
| 18.04 | Affected | โ |
| 16.04 | Affected | โ |
| 12.04 | Affected | โ |
Debian Mixed 6 releases
| Version | Status | Fixed in |
|---|---|---|
| trixie | Fixed | 3.29.0-2 |
| sid | Fixed | 3.29.0-2 |
| forky | Fixed | 3.29.0-2 |
| bullseye | Fixed | 3.29.0-2 |
| bookworm | Fixed | 3.29.0-2 |
| 9.0 | Affected | โ |
Red Hat Fixed 1 release
| Version | Status | Fixed in |
|---|---|---|
| 8 | Fixed | โ |
Rocky Linux Fixed 1 release
| Version | Status | Fixed in |
|---|---|---|
| 8 | Fixed | โ |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| sqlite | sqlite | {"startIncluding":"3.8.5","endIncluding":"3.29.0"} | |
| netapp | active_iq_unified_manager | {"startIncluding":"7.3"} | |
| netapp | active_iq_unified_manager | {"startIncluding":"9.5"} | |
| netapp | e-series_santricity_os_controller | {"startIncluding":"11.0.0","endIncluding":"11.60.3"} | |
| netapp | oncommand_insight | - | |
| netapp | oncommand_workflow_automation | - | |
| netapp | ontap_select_deploy_administration_utility | - | |
| netapp | santricity_unified_manager | - | |
| netapp | steelstore_cloud_integrated_storage | - | |
| tenable | nessus_agent | {"endIncluding":"8.2.3"} | |
| oracle | communications_design_studio | 7.3.4.3.0 | |
| oracle | communications_design_studio | 7.3.5.5.0 | |
| oracle | communications_design_studio | 7.4.0.4.0 | |
| oracle | jdk | 1.8.0 | |
| oracle | jre | 1.8.0 | |
| oracle | mysql | {"startIncluding":"8.0.0","endIncluding":"8.0.18"} | |
| oracle | outside_in_technology | 8.5.4 | |
| mcafee | policy_auditor | {"endExcluding":"6.5.1"} | 6.5.1 |
References
- https://errata.rockylinux.org/RLSA-2021:1968
- https://www.suse.com/security/cve/CVE-2019-16168.html
- https://security-tracker.debian.org/tracker/CVE-2019-16168
- https://errata.almalinux.org/8/ALSA-2021-1968.html
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00032.html
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00033.html
- https://kc.mcafee.com/corporate/index?page=content&id=SB10365
- https://lists.debian.org/debian-lts-announce/2020/08/msg00037.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XZARJHJJDBHI7CE5PZEBXS5HKK6HXKW2/
- https://security.gentoo.org/glsa/202003-16
- https://security.netapp.com/advisory/ntap-20190926-0003/
- https://security.netapp.com/advisory/ntap-20200122-0003/
- https://usn.ubuntu.com/4205-1/
- https://www.mail-archive.com/sqlite-users%40mailinglists.sqlite.org/msg116312.html
- https://www.oracle.com/security-alerts/cpuapr2020.html
- https://www.oracle.com/security-alerts/cpujan2020.html
- https://www.sqlite.org/src/info/e4598ecbdd18bd82945f6029013296690e719a62
- https://www.sqlite.org/src/timeline?c=98357d8c1263920b
- https://www.tenable.com/security/tns-2021-08
- https://www.tenable.com/security/tns-2021-11
- https://www.tenable.com/security/tns-2021-14
- https://access.redhat.com/errata/RHSA-2020:4442
- https://access.redhat.com/errata/RHSA-2021:1968
CWEs
CWE-369
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.