Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-7104

Опубликовано: 29 дек. 2023
Источник: debian

Описание

A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionReadRecord of the file ext/session/sqlite3session.c of the component make alltest Handler. The manipulation leads to heap-based buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-248999.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
sqlite3fixed3.43.1-1package
sqlite3fixed3.40.1-2+deb12u1bookwormpackage
sqlite3no-dsabusterpackage

Примечания

  • https://sqlite.org/forum/forumpost/5bcbf4571c

  • Fixed by: https://sqlite.org/src/info/0e4e7a05c4204b47

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 1 года назад

A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionReadRecord of the file ext/session/sqlite3session.c of the component make alltest Handler. The manipulation leads to heap-based buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-248999.

CVSS3: 7.3
redhat
больше 1 года назад

A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionReadRecord of the file ext/session/sqlite3session.c of the component make alltest Handler. The manipulation leads to heap-based buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-248999.

CVSS3: 5.5
nvd
больше 1 года назад

A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionReadRecord of the file ext/session/sqlite3session.c of the component make alltest Handler. The manipulation leads to heap-based buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-248999.

CVSS3: 7.3
msrc
больше 1 года назад

Описание отсутствует

rocky
больше 1 года назад

Moderate: sqlite security update