Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
This update for sqlite3 fixes the following issues: sqlite3 is sync version 3.36.0 from Factory (jsc#SLE-16032). The following CVEs have been fixed in upstream releases up to this point, but were not mentioned in the change log so far: * bsc#1173641, CVE-2020-15358: heap-based buffer overflow in multiSelectOrderBy due to mishandling of query-flattener optimization * bsc#1164719, CVE-2020-9327: NULL pointer dereference and segmentation fault because of generated column optimizations in isAuxiliaryVtabOperator * bsc#1160439, CVE-2019-20218: selectExpander in select.c proceeds with WITH stack unwinding even after a parsing error * bsc#1160438, CVE-2019-19959: memory-management error via ext/misc/zipfile.c involving embedded '\0' input
#1157818 #1158812 #1158958 #1158959 #1158960
#1159491 #1159715 #1159847 #1159850 #1160309
#1160438 #1160439 #1164719 #1172091 #1172115
#1172234 #1172236 #1172240 #1173641 #928700
#928701 SLE-16032
Cross- CVE-2015-3414 CVE-2015-3415 CVE-2016-6153
CVE-2017-10989 CVE-2017-2518 CVE-2018-20346
CVE-2018-8740 CVE-2019-16168 CVE-2019-19244
CVE-2019-19317 CVE-2019-19603 CVE-2019-19645
CVE-2019-19646 CVE-2019-19880 CVE-2019-19923
CVE-2019-19924 CVE-2019-19925 CVE-2019-19926
CVE-2019-19959 CVE-2019-20218 CVE-2019-8457
CVE-2020-13434 CVE-2020-13435 CVE-2020-13630
CVE-2020-13631 CVE-2020-13632 CVE-2020-15358
CVE-2020-9327
CVSS scores:
CVE-2015-3414 (SUSE): 7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Get the latest Linux and open source security news straight to your inbox.