Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

SUSE Linux 12-SP5: 2021:3215-1 Important: sqlite3 Buffer Overflow

suse
Calendar Grey September 23, 2021
Scroller Suse
SUSE Security Bulletin for sqlite3 addresses severe exploit risks with comprehensive patch guidelines and threat severity levels.
An update that fixes 28 vulnerabilities, contains one feature is now available

Summary

This update for sqlite3 fixes the following issues: sqlite3 is sync version 3.36.0 from Factory (jsc#SLE-16032). The following CVEs have been fixed in upstream releases up to this point, but were not mentioned in the change log so far: * bsc#1173641, CVE-2020-15358: heap-based buffer overflow in multiSelectOrderBy due to mishandling of query-flattener optimization * bsc#1164719, CVE-2020-9327: NULL pointer dereference and segmentation fault because of generated column optimizations in isAuxiliaryVtabOperator * bsc#1160439, CVE-2019-20218: selectExpander in select.c proceeds with WITH stack unwinding even after a parsing error * bsc#1160438, CVE-2019-19959: memory-management error via ext/misc/zipfile.c involving embedded '\0' input

References

#1157818 #1158812 #1158958 #1158959 #1158960

#1159491 #1159715 #1159847 #1159850 #1160309

#1160438 #1160439 #1164719 #1172091 #1172115

#1172234 #1172236 #1172240 #1173641 #928700

#928701 SLE-16032

Cross- CVE-2015-3414 CVE-2015-3415 CVE-2016-6153

CVE-2017-10989 CVE-2017-2518 CVE-2018-20346

CVE-2018-8740 CVE-2019-16168 CVE-2019-19244

CVE-2019-19317 CVE-2019-19603 CVE-2019-19645

CVE-2019-19646 CVE-2019-19880 CVE-2019-19923

CVE-2019-19924 CVE-2019-19925 CVE-2019-19926

CVE-2019-19959 CVE-2019-20218 CVE-2019-8457

CVE-2020-13434 CVE-2020-13435 CVE-2020-13630

CVE-2020-13631 CVE-2020-13632 CVE-2020-15358

CVE-2020-9327

CVSS scores:

CVE-2015-3414 (SUSE): 7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2021:3215-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.