Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-46908

Опубликовано: 12 дек. 2022
Источник: debian
EPSS Низкий

Описание

SQLite through 3.40.0, when relying on --safe for execution of an untrusted CLI script, does not properly implement the azProhibitedFunctions protection mechanism, and instead allows UDF functions such as WRITEFILE.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
sqlite3fixed3.40.0-2package
sqlite3not-affectedbullseyepackage
sqlite3not-affectedbusterpackage
sqlitenot-affectedpackage

Примечания

  • https://sqlite.org/forum/forumpost/07beac8056151b2f

  • Fixed by: https://sqlite.org/src/info/cefc032473ac5ad2

EPSS

Процентиль: 26%
0.00088
Низкий

Связанные уязвимости

CVSS3: 7.3
ubuntu
больше 2 лет назад

SQLite through 3.40.0, when relying on --safe for execution of an untrusted CLI script, does not properly implement the azProhibitedFunctions protection mechanism, and instead allows UDF functions such as WRITEFILE.

CVSS3: 7.3
redhat
больше 2 лет назад

SQLite through 3.40.0, when relying on --safe for execution of an untrusted CLI script, does not properly implement the azProhibitedFunctions protection mechanism, and instead allows UDF functions such as WRITEFILE.

CVSS3: 7.3
nvd
больше 2 лет назад

SQLite through 3.40.0, when relying on --safe for execution of an untrusted CLI script, does not properly implement the azProhibitedFunctions protection mechanism, and instead allows UDF functions such as WRITEFILE.

CVSS3: 7.3
msrc
больше 2 лет назад

Описание отсутствует

suse-cvrf
почти 2 года назад

Security update for sqlite3

EPSS

Процентиль: 26%
0.00088
Низкий
Уязвимость CVE-2022-46908