Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

Mageia 6: MGASA-2019-0240 Critical: sqlite3 Input Issues and DoS

mageia
Calendar Grey September 6, 2019
Dist Mageia Esm H88
New sqlite3 updates released on Sep 06, 2019, target significant security vulnerabilities, resolving various essential weaknesses.
Updated sqlite3 packages fix security vulnerabilities: It was discovered that SQLite incorrectly handled certain inputs

Summary

Updated sqlite3 packages fix security vulnerabilities:
It was discovered that SQLite incorrectly handled certain inputs. An attacker could possibly use this issue to access sensitive information (CVE-2019-8457).
It was discovered that SQLite incorrectly handled certain queries. An attacker could possibly use this issue to access sensitive information (CVE-2019-9936).
It was discovered that SQLite incorrectly handled certain inputs. An attacker could possibly use this issue to cause a crash or execute arbitrary code (CVE-2019-9937).

References

- https://bugs.mageia.org/show_bug.cgi?id=24750

- https://ubuntu.com/security/notices/USN-4019-1

- https://www.cve.org/CVERecord?id=CVE-2019-8457

- https://www.cve.org/CVERecord?id=CVE-2019-9936

- https://www.cve.org/CVERecord?id=CVE-2019-9937

Resolution

SRPMS

- 6/core/sqlite3-3.28.0-1.mga6

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 06 Sep 2019
URL: https://advisories.mageia.org/MGASA-2019-0240.html
Type: security
CVE: CVE-2019-8457, CVE-2019-9936, CVE-2019-9937

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here