Alerts This Week
Warning Icon 1 914
Alerts This Week
Warning Icon 1 914

Fedora 25: 2017-447e926933 Critical: sqlite Heap Overflow Fix

fedora
Calendar Grey July 14, 2017
Dist Fedora Esm H88
Mitigating CVE-2017-10990, this patch fixes a critical stack overflow in libxml2 on Ubuntu 18.04, bolstering overall system integrity.
Security fix for CVE-2017-10989: Heap-buffer overflow in the getNodeSize function

Summary

SQLite is a C library that implements an SQL database engine. A large

subset of SQL92 is supported. A complete database is stored in a

single disk file. The API is designed for convenience and ease of use.

Applications that link against SQLite can enjoy the power and

flexibility of an SQL database without the administrative hassles of

supporting a separate database server. Version 2 and version 3 binaries

are named to permit each to be installed on a single host

Security fix for CVE-2017-10989: Heap-buffer overflow in the getNodeSize

function

[ 1 ] Bug #1469672 - CVE-2017-10989 sqlite: Heap-buffer overflow in the getNodeSize function

https://bugzilla.redhat.com/show_bug.cgi?id=1469672

su -c 'dnf upgrade sqlite' at the command line.

For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 25
Version: 3.14.2
Release: 2.fc25
Summary: Library that implements an embeddable SQL database engine

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here