Fedora Linux 17 (Beefy Miracle)
Fedora Linux 17 (Beefy Miracle)
The Fedora Linux 17 (Beefy Miracle) reached end of service life on Jul 30, 2013 — Fedora no longer ships security patches or fixes for it. Our third-party support keeps it safe to run: 24/7 engineers manage issues, remediate vulnerabilities, and help you maintain compliance.
24/7 engineers own your Fedora Linux 17 (Beefy Miracle) incidents end to end.
Mitigation and patch-around guidance when the vendor no longer ships fixes.
Controls evidence and documentation that keep auditors satisfied.
Specifications
- product
- fedora
- release
- 17
- product Label
- Fedora Linux
- release Label
- 17 (Beefy Miracle)
- codename
- Beefy Miracle
- lts
- latest Version
- release Date
- 2012-05-29
- maintained
- source Url
- https://endoflife.date/fedora
Lifecycle Dates
- End of Service Life
- Jul 30, 2013
- Last OEM Support
- Jul 30, 2013
OEM vs. 3rd Party Support
See how third-party support compares to the vendor contract for Fedora Linux 17 (Beefy Miracle) — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.
| Feature | OEM Support | 3rd Party Support |
|---|---|---|
| Post-EOSL Support | ||
| Break/Fix Support | Until EOSL | |
| 24/7 Monitoring | ||
| Vulnerability Scanning & Remediation | ||
| Managed Operations | ||
| Procedure & Configuration Review | ||
| Compliance & Audit Documentation | Limited | |
| Discounted Migration to Other Platforms |
Why Choose 3rd Party Support for Fedora Linux 17 (Beefy Miracle)?
Vulnerability Remediation
Scanning, mitigation and patch-around guidance for Fedora Linux 17 (Beefy Miracle) when the vendor no longer ships fixes.
Compliance Maintenance
Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.
24/7 Expert Support
Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.
Fedora Linux 17 (Beefy Miracle) Support: Frequently Asked Questions
Is the Fedora Linux 17 (Beefy Miracle) still supported?
Fedora ended support for the Fedora Linux 17 (Beefy Miracle) on Jul 30, 2013 — no more patches or fixes from the vendor. Third-party support keeps it covered: our engineers manage issues, remediate vulnerabilities, and help you maintain compliance for as long as you run it.
When is the Fedora Linux 17 (Beefy Miracle) end of service life (EOSL) date?
Fedora lists the end of service life for the Fedora Linux 17 (Beefy Miracle) as Jul 30, 2013.
Can I keep using the Fedora Linux 17 (Beefy Miracle) after its EOSL date?
Yes. EOSL means Fedora stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.
How much does third-party support for the Fedora Linux 17 (Beefy Miracle) cost?
Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.
Known Vulnerabilities Affecting Fedora Linux 17 (Beefy Miracle)
85 published CVEs affect the Fedora Linux 17 (Beefy Miracle), including 28 rated critical or high severity. Fedora no longer ships security patches for this release — our engineers provide mitigation guidance, workarounds and hardening support.
| CVE | Severity | CVSS | Published | Summary |
|---|---|---|---|---|
| CVE-2013-7088 | CRITICAL | 9.8 | Nov 15, 2019 | ClamAV before 0.97.7 has buffer overflow in the libclamav component |
| CVE-2013-7087 | CRITICAL | 9.8 | Nov 15, 2019 | ClamAV before 0.97.7 has WWPack corrupt heap memory |
| CVE-2019-11235 | CRITICAL | 9.8 | Apr 22, 2019 | FreeRADIUS before 3.0.19 mishandles the "each participant verifies that the received scalar is within a range, and that the received group element is a valid point on the curve being used" protection mechanism, aka a "Dragonblood" issue, a similar issue to CVE-2019-9498 and CVE-2019-9499. |
| CVE-2019-11234 | CRITICAL | 9.8 | Apr 22, 2019 | FreeRADIUS before 3.0.19 does not prevent use of reflection for authentication spoofing, aka a "Dragonblood" issue, a similar issue to CVE-2019-9497. |
| CVE-2012-3363 | CRITICAL | 9.1 | Feb 13, 2013 | Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE element in an XML-RPC request, aka an XML external entity (XXE) injection attack. |
| CVE-2012-6075 | HIGH | 9.3 | Feb 13, 2013 | Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e1000.c) in QEMU 1.3.0-rc2 and other versions, when the SBP and LPE flags are disabled, allows remote attackers to cause a denial of service (guest OS crash) and possibly execute arbitrary guest code via a large packet. |
| CVE-2019-10132 | HIGH | 8.8 | May 22, 2019 | A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A missing SocketMode configuration parameter allows any user on the host to connect using virtlockd-admin-sock or virtlogd-admin-sock and perform administrative tasks against the virtlockd and virtlogd daemons. |
| CVE-2011-3045 | HIGH | 8.8 | Mar 22, 2012 | Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file, a different vulnerability than CVE-2011-3026. |
| CVE-2012-1168 | HIGH | 8.2 | Nov 14, 2019 | Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified. |
| CVE-2012-1615 | HIGH | 7.8 | Dec 6, 2019 | A Privilege Escalation vulnerability exits in Fedoraproject Sectool due to an incorrect DBus file. |
| CVE-2012-4480 | HIGH | 7.8 | Dec 2, 2019 | mom creates world-writable pid files in /var/run |
| CVE-2010-4661 | HIGH | 7.8 | Nov 13, 2019 | udisks before 1.0.3 allows a local user to load arbitrary Linux kernel modules. |
| CVE-2018-5345 | HIGH | 7.8 | Jan 12, 2018 | A stack-based buffer overflow within GNOME gcab through 0.7.4 can be exploited by malicious attackers to cause a crash or, potentially, execute arbitrary code via a crafted .cab file. |
| CVE-2013-1895 | HIGH | 7.5 | Jan 28, 2020 | The py-bcrypt module before 0.3 for Python does not properly handle concurrent memory access, which allows attackers to bypass authentication via multiple authentication requests, which trigger the password hash to be overwritten. |
| CVE-2012-5645 | HIGH | 7.5 | Dec 30, 2019 | A denial of service flaw was found in the way the server component of Freeciv before 2.3.4 processed certain packets. A remote attacker could send a specially-crafted packet that, when processed would lead to memory exhaustion or excessive CPU consumption. |
| CVE-2012-5535 | HIGH | 7.5 | Nov 25, 2019 | gnome-system-log polkit policy allows arbitrary files on the system to be read |
| CVE-2012-4524 | HIGH | 7.5 | Nov 21, 2019 | xlockmore before 5.43 'dclock' security bypass vulnerability |
| CVE-2013-7089 | HIGH | 7.5 | Nov 15, 2019 | ClamAV before 0.97.7: dbg_printhex possible information leak |
| CVE-2012-1170 | HIGH | 7.5 | Nov 14, 2019 | Moodle before 2.2.2 has an external enrolment plugin context check issue where capability checks are not thorough |
| CVE-2012-1156 | HIGH | 7.5 | Nov 14, 2019 | Moodle before 2.2.2 has users' private files included in course backups |
Showing the 20 most severe of 85 known CVEs.
Get Third Party Support