Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Mageia 8: MGASA-2023-0208 Moderate: Sqlite Denial Of Service

mageia
Calendar Grey June 28, 2023
Dist Mageia Esm H88
Recent updates to sqlite packages for Mageia address problems related to the management of temporary directories, mitigating risks of data exposure.
os_unix.c in SQLite before 3.13.0 improperly implements the temporary directory search algorithm, which might allow local users to obtain sensitive information, cause a denial of s...

Summary

os_unix.c in SQLite before 3.13.0 improperly implements the temporary directory search algorithm, which might allow local users to obtain sensitive information, cause a denial of service (application crash), or have unspecified other impact by leveraging use of the current working directory for temporary files. (CVE-2016-6153) In SQLite through 3.22.0, databases whose schema is corrupted using a CREATE TABLE AS statement could cause a NULL pointer dereference, related to build.c and prepare (CVE-2018-8740)

References

- https://bugs.mageia.org/show_bug.cgi?id=32018

- https://lists.debian.org/debian-lts-announce/2023/05/msg00022.html

- https://www.cve.org/CVERecord?id=CVE-2016-6153

- https://www.cve.org/CVERecord?id=CVE-2018-8740

Resolution

SRPMS

- 8/core/sqlite-2.8.17-26.1.mga8

Publication date: 28 Jun 2023
URL: https://advisories.mageia.org/MGASA-2023-0208.html
Type: security
CVE: CVE-2016-6153, CVE-2018-8740

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here