Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-6153

Опубликовано: 26 сент. 2016
Источник: debian

Описание

os_unix.c in SQLite before 3.13.0 improperly implements the temporary directory search algorithm, which might allow local users to obtain sensitive information, cause a denial of service (application crash), or have unspecified other impact by leveraging use of the current working directory for temporary files.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
sqlite3fixed3.13.0-1package
sqlite3fixed3.8.7.1-1+deb8u2jessiepackage
sqliteremovedpackage

Примечания

  • http://www.sqlite.org/cgi/src/info/67985761aa93fb61

  • http://www.sqlite.org/cgi/src/info/b38fe522cfc971b3

  • and possibly http://www.sqlite.org/cgi/src/info/614bb709d34e1148

  • https://www.korelogic.com/Resources/Advisories/KL-001-2016-003.txt

  • Vulnerable code in os.c:sqliteOsTempFileName() for sqlite(v2)

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 9 лет назад

os_unix.c in SQLite before 3.13.0 improperly implements the temporary directory search algorithm, which might allow local users to obtain sensitive information, cause a denial of service (application crash), or have unspecified other impact by leveraging use of the current working directory for temporary files.

CVSS3: 2.2
redhat
больше 9 лет назад

os_unix.c in SQLite before 3.13.0 improperly implements the temporary directory search algorithm, which might allow local users to obtain sensitive information, cause a denial of service (application crash), or have unspecified other impact by leveraging use of the current working directory for temporary files.

CVSS3: 5.9
nvd
больше 9 лет назад

os_unix.c in SQLite before 3.13.0 improperly implements the temporary directory search algorithm, which might allow local users to obtain sensitive information, cause a denial of service (application crash), or have unspecified other impact by leveraging use of the current working directory for temporary files.

suse-cvrf
больше 9 лет назад

Security update for sqlite3

suse-cvrf
больше 9 лет назад

Security update for sqlite3