Описание
zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive.
Отчет
The zip extension was introduced in sqlite-3.22.0, therefore previous versions are not affected by this flaw.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 5 | sqlite | Not affected | ||
| Red Hat Enterprise Linux 6 | sqlite | Not affected | ||
| Red Hat Enterprise Linux 7 | sqlite | Not affected | ||
| Red Hat Enterprise Linux 6 Supplementary | chromium-browser | Fixed | RHSA-2020:0514 | 17.02.2020 |
| Red Hat Enterprise Linux 8 | sqlite | Fixed | RHSA-2020:1810 | 28.04.2020 |
| Red Hat Enterprise Linux 8 | sqlite | Fixed | RHSA-2020:1810 | 28.04.2020 |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive.
zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive.
zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL ...
zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive.
Уязвимость функции zipfileUpdate() системы управления базами данных SQLite, позволяющая нарушителю вызвать отказ в обслуживании
7.5 High
CVSS3