Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

Fedora 26: FEDORA-2017-357f9df699 Moderate: Sqlite Heap Overflow

fedora
Calendar Grey July 16, 2017
Dist Fedora Esm H88
Fedora has released an update targeting the heap-buffer overflow vulnerability identified in SQLite, now upgraded to version max-3.19.3, to bolster security and enhance overall performance.
Security fix for CVE-2017-10989: Heap-buffer overflow in the getNodeSize function Additionally sqlite has been updated to version 3.19.3, and spatialite-tools rebuilt for the updat...

Summary

SQLite is a C library that implements an SQL database engine. A large

subset of SQL92 is supported. A complete database is stored in a

single disk file. The API is designed for convenience and ease of use.

Applications that link against SQLite can enjoy the power and

flexibility of an SQL database without the administrative hassles of

supporting a separate database server. Version 2 and version 3 binaries

are named to permit each to be installed on a single host

Security fix for CVE-2017-10989: Heap-buffer overflow in the getNodeSize

function Additionally sqlite has been updated to version 3.19.3, and

spatialite-tools rebuilt for the update.

[ 1 ] Bug #1469672 - CVE-2017-10989 sqlite: Heap-buffer overflow in the getNodeSize function

https://bugzilla.redhat.com/show_bug.cgi?id=1469672

su -c 'dnf upgrade sqlite' at the command line.

For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Severity
important
Lowest
Low
Medium
High
Critical

Product: Fedora 26
Version: 3.19.3
Release: 1.fc26
Summary: Library that implements an embeddable SQL database engine

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here