MGASA-2019-0240 - Updated sqlite3 packages fix security vulnerabilities

Publication date: 06 Sep 2019
URL: https://advisories.mageia.org/MGASA-2019-0240.html
Type: security
Affected Mageia releases: 6
CVE: CVE-2019-8457,
     CVE-2019-9936,
     CVE-2019-9937

Updated sqlite3 packages fix security vulnerabilities:

It was discovered that SQLite incorrectly handled certain inputs. An
attacker could possibly use this issue to access sensitive information
(CVE-2019-8457).

It was discovered that SQLite incorrectly handled certain queries. An
attacker could possibly use this issue to access sensitive information
(CVE-2019-9936).

It was discovered that SQLite incorrectly handled certain inputs. An
attacker could possibly use this issue to cause a crash or execute
arbitrary code (CVE-2019-9937).

References:
- https://bugs.mageia.org/show_bug.cgi?id=24750
- https://ubuntu.com/security/notices/USN-4019-1
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8457
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9936
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9937

SRPMS:
- 6/core/sqlite3-3.28.0-1.mga6

Mageia 2019-0240: sqlite3 security update

Updated sqlite3 packages fix security vulnerabilities: It was discovered that SQLite incorrectly handled certain inputs

Summary

Updated sqlite3 packages fix security vulnerabilities:
It was discovered that SQLite incorrectly handled certain inputs. An attacker could possibly use this issue to access sensitive information (CVE-2019-8457).
It was discovered that SQLite incorrectly handled certain queries. An attacker could possibly use this issue to access sensitive information (CVE-2019-9936).
It was discovered that SQLite incorrectly handled certain inputs. An attacker could possibly use this issue to cause a crash or execute arbitrary code (CVE-2019-9937).

References

- https://bugs.mageia.org/show_bug.cgi?id=24750

- https://ubuntu.com/security/notices/USN-4019-1

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8457

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9936

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9937

Resolution

MGASA-2019-0240 - Updated sqlite3 packages fix security vulnerabilities

SRPMS

- 6/core/sqlite3-3.28.0-1.mga6

Severity
Publication date: 06 Sep 2019
URL: https://advisories.mageia.org/MGASA-2019-0240.html
Type: security
CVE: CVE-2019-8457, CVE-2019-9936, CVE-2019-9937

Related News