MGASA-2023-0208
Dashboard / Vulnerabilities / MGASA-2023-0208
Summary: Updated sqlite packages fix security vulnerability
Details: os_unix.c in SQLite before 3.13.0 improperly implements the temporary directory search algorithm, which might allow local users to obtain sensitive information, cause a denial of service (application crash), or have unspecified other impact by leveraging use of the current working directory for temporary files. (CVE-2016-6153) In SQLite through 3.22.0, databases whose schema is corrupted using a CREATE TABLE AS statement could cause a NULL pointer dereference, related to build.c and prepare (CVE-2018-8740)
References: https://advisories.mageia.org/MGASA-2023-0208.html, https://bugs.mageia.org/show_bug.cgi?id=32018, https://www.debian.org/lts/security/2023/dla-3431
Affected packages
Package
Name: sqlite
Purl: pkg:rpm/mageia/sqlite?arch=source&distro=mageia-8
Affected ranges
Type: ECOSYSTEM
Events:
