MGASA-2024-0073 - Updated sqlite3 packages fix security vulnerabilities

Publication date: 20 Mar 2024
URL: https://advisories.mageia.org/MGASA-2024-0073.html
Type: security
Affected Mageia releases: 9
CVE: CVE-2023-2137,
     CVE-2023-7104

The updated packages fix security vulnerabilities:
Heap buffer overflow in sqlite. (CVE-2023-2137)
A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified
as critical. This issue affects the function sessionReadRecord of the
file ext/session/sqlite3session.c of the component make alltest Handler.
The manipulation leads to heap-based buffer overflow. (CVE-2023-7104)

References:
- https://bugs.mageia.org/show_bug.cgi?id=31868
- https://chromereleases.googleblog.com/2023/04/stable-channel-update-for-desktop_18.html
- https://ubuntu.com/security/notices/USN-6566-1
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2137
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-7104

SRPMS:
- 9/core/sqlite3-3.40.1-1.1.mga9

Mageia 2024-0073: sqlite3 security update

The updated packages fix security vulnerabilities: Heap buffer overflow in sqlite

Summary

The updated packages fix security vulnerabilities: Heap buffer overflow in sqlite. (CVE-2023-2137) A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionReadRecord of the file ext/session/sqlite3session.c of the component make alltest Handler. The manipulation leads to heap-based buffer overflow. (CVE-2023-7104)

References

- https://bugs.mageia.org/show_bug.cgi?id=31868

- https://chromereleases.googleblog.com/2023/04/stable-channel-update-for-desktop_18.html

- https://ubuntu.com/security/notices/USN-6566-1

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2137

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-7104

Resolution

MGASA-2024-0073 - Updated sqlite3 packages fix security vulnerabilities

SRPMS

- 9/core/sqlite3-3.40.1-1.1.mga9

Severity
Publication date: 20 Mar 2024
URL: https://advisories.mageia.org/MGASA-2024-0073.html
Type: security
CVE: CVE-2023-2137, CVE-2023-7104

Related News