Gregor Kopf of Secfault Security GmbH discovered that HSQLDB, a Java SQL database engine, allowed the execution of spurious scripting commands in .script and .log files. Hsqldb supports a "SCRIPT" keyword which is normally used to record the commands input by the database admin to output . -------------------------------------------------------------------------Debian LTS Advisory DLA-3468-1
**MariaDB 10.5.18 & Galera 26.4.13** Release notes: https://mariadb.com/docs/release-notes/community-server/old-releases/mariadb-10-5-series/mariadb-10-5-18-release-notes. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-e0e9a43546 2022-11-30 01:33:59.394774 --------------------------------------------------------------------------------Name : galera Product : Fedora 37 Version : 26.4.13 Release : 1.fc37 URL : https://mariadb.com/products/enterprise/galera-cluster/ Summary : Synchronous multi-master wsrep provider (replication engine) Description : Galera is a fast synchronous multimaster wsrep provider (replication engine) for transactional databases and similar applications. For more information about wsrep API see https://github.com/mariadb-corporation/wsrep-API repository. For a description of Galera replication engine see https://mariadb.com/products/enterprise/galera-cluster/ web. --------------------------------------------------------------------------------Update Information: **MariaDB 10.5.18 & Galera 26.4.13** Release notes: https://mariadb.com/docs/release-notes/community-server/old-releases/mariadb-10-5-series/mariadb-10-5-18-release-notes --------------------------------------------------------------------------------ChangeLog: * Tue Nov 15 2022 Michal Schorm - 26.4.13-1 - Rebase to 26.4.13 * Wed Aug 24 2022 Michal Schorm - 26.4.12-1 - Rebase to 26.4.12 --------------------------------------------------------------------------------References: [ 1 ] Bug #2114892 - CVE-2022-32081 CVE-2022-32082 CVE-2022-32084 CVE-2022-32089 CVE-2022-32091 CVE-2022-38791 mariadb: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2114892 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-e0e9a43546' at thecommand line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
**MariaDB 10.3.26** **MariaDB connector C/C++ 3.1.11** **Galera 25.3.26** Release notes: https://mariadb.com/docs/release-notes/community-server/old-releases/release-notes-mariadb-10-3-series/mariadb-10326-release-notes https://mariadb.com/docs/release-notes/connectors/c/3.1/3.1.11 ---- **MariaDB 10.3.25** Release notes: https://mariadb.com/docs/release-notes/community-server/old-releases/release-notes-mariadb-10-3-series/mariadb-10325-release-notes. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-ac2d47d89a 2020-11-11 01:31:11.923446 --------------------------------------------------------------------------------Name : galera Product : Fedora 31 Version : 25.3.31 Release : 1.fc31 URL : https://mariadb.com/products/enterprise/galera-cluster/ Summary : Synchronous multi-master wsrep provider (replication engine) Description : Galera is a fast synchronous multi-master wsrep provider (replication engine) for transactional databases and similar applications. For more information about wsrep API see https://launchpad.net/wsrep. For a description of Galera replication engine see . --------------------------------------------------------------------------------Update Information: **MariaDB 10.3.26** **MariaDB connector C/C++ 3.1.11** **Galera 25.3.26** Release notes: https://mariadb.com/docs/release-notes/community-server/old-releases/release-notes-mariadb-10-3-series/mariadb-10326-release-notes https://mariadb.com/docs/release-notes/connectors/c/3.1/3.1.11 ----**MariaDB 10.3.25** Release notes: https://mariadb.com/docs/release-notes/community-server/old-releases/release-notes-mariadb-10-3-series/mariadb-10325-release-notes --------------------------------------------------------------------------------ChangeLog: * Wed Nov 4 2020 Michal Schorm - 25.3.31-1 - Rebase to 25.3.31 * Mon Oct 26 2020 Michal Schorm - 25.3.30-1 - Rebase to 25.3.30 * Fri Jun 5 2020 Michal Schorm - 25.3.29-1 - Rebase to 25.3.29 Resolves: rhbz#1546787 --------------------------------------------------------------------------------References: [ 1 ] Bug #1830119 - CVE-2020-2752 CVE-2020-2760 CVE-2020-2812 CVE-2020-2814 mariadb:10.3/mariadb: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1830119 [ 2 ] Bug #1843796 - CVE-2020-13249 mariadb:10.3/mariadb: mariadb-connector-c: Improper validation of content in a OK packet received from server [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1843796 [ 3 ] Bug #1846527 - CVE-2020-2780 mariadb:10.3/mariadb: mysql: Server: DML unspecified vulnerability (CPU Apr 2020) [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1846527 [ 4 ] Bug #1894078 - CVE-2020-14765 CVE-2020-14776 CVE-2020-14789 CVE-2020-14812 mariadb: various flaws [fedora-31] https://bugzilla.redhat.com/show_bug.cgi?id=1894078 [ 5 ] Bug #1894663 - mariadb-connector-c-3.1.11 is available https://bugzilla.redhat.com/show_bug.cgi?id=1894663 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-ac2d47d89a' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Several security issues were fixed in SQLite.. =========================================================================Ubuntu Security Notice USN-4205-1 December 02, 2019 sqlite3 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 19.10 - Ubuntu 19.04 - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 12.04 ESM Summary: Several security issues were fixed in SQLite. Software Description: - sqlite3: C library that implements an SQL database engine Details: It was discovered that SQLite incorrectly handled certain schemas. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 12.04 ESM. (CVE-2018-8740) It was discovered that SQLite incorrectly handled certain schemas. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 19.04. (CVE-2019-16168) It was discovered that SQLite incorrectly handled certain schemas. An attacker could possibly use this issue to mishandles some expressions. This issue only affected Ubuntu 19.04 and Ubuntu 19.10. (CVE-2019-19242) It was discovered that SQLite incorrectly handled certain queries. An attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 19.04 and Ubuntu 19.10. (CVE-2019-19244) It was discovered that SQLite incorrectly handled certain SQL commands. An attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 19.04. (CVE-2019-5018) It was discovered that SQLite incorrectly handled certain commands. An attacker could possibly use this issue to execute arbitrary code. (CVE-2019-5827) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 19.10: libsqlite3-0 3.29.0-2ubuntu0.1 sqlite3 3.29.0-2ubuntu0.1 Ubuntu 19.04: libsqlite3-0 3.27.2-2ubuntu0.2 sqlite3 3.27.2-2ubuntu0.2 Ubuntu 18.04 LTS: libsqlite3-0 3.22.0-1ubuntu0.2 sqlite3 3.22.0-1ubuntu0.2 Ubuntu 16.04 LTS: libsqlite3-0 3.11.0-1ubuntu1.3 sqlite3 3.11.0-1ubuntu1.3 Ubuntu 12.04 ESM: libsqlite3-0 3.7.9-2ubuntu1.4 sqlite3 3.7.9-2ubuntu1.4 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4205-1 CVE-2018-8740, CVE-2019-16168, CVE-2019-19242, CVE-2019-19244, CVE-2019-5018, CVE-2019-5827 Package Information: https://launchpad.net/ubuntu/+source/sqlite3/3.29.0-2ubuntu0.1 https://launchpad.net/ubuntu/+source/sqlite3/3.27.2-2ubuntu0.2 https://launchpad.net/ubuntu/+source/sqlite3/3.22.0-1ubuntu0.2 https://launchpad.net/ubuntu/+source/sqlite3/3.11.0-1ubuntu1.3 . Numerous vulnerabilities patched in SQLite for Ubuntu, posing risks such as DoS and potential code execution exploits. Ensure you update immediately!. SQL Injection, SQLite Security, Database Vulnerabilities, Ubuntu Security Update. . Severity: Critical. LinuxSecurity.com Team
- update to 3.26.0.0. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-49f80a78bc 2019-08-13 01:58:20.879284 --------------------------------------------------------------------------------Name : mingw-sqlite Product : Fedora 29 Version : 3.26.0.0 Release : 1.fc29 URL : https://sqlite.org/ Summary : MinGW Windows port of sqlite embeddable SQL database engine Description : SQLite is a C library that implements an SQL database engine. A large subset of SQL92 is supported. A complete database is stored in a single disk file. The API is designed for convenience and ease of use. Applications that link against SQLite can enjoy the power and flexibility of an SQL database without the administrative hassles of supporting a separate database server. Version 2 and version 3 binaries are named to permit each to be installed on a single host This package contains cross-compiled libraries and development tools for Windows. --------------------------------------------------------------------------------Update Information: - update to 3.26.0.0 --------------------------------------------------------------------------------ChangeLog: * Thu Feb 7 2019 Thomas Sailer - 3.26.0.0-1 - update to 3.26.0.0 --------------------------------------------------------------------------------References: [ 1 ] Bug #1659908 - CVE-2018-20346 mingw-sqlite: sqlite: Multiple flaws in sqlite which can be triggered via corrupted internal databases (Magellan) [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1659908 [ 2 ] Bug #1558808 - CVE-2018-8740 mingw-sqlite: sqlite: NULL pointer dereference with databases with schema corrupted with CREATE TABLE AS allows for denial of service [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1558808 [ 3 ] Bug #1352440 - CVE-2016-6153 mingw-sqlite: sqlite: Tempdir selection vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1352440 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-49f80a78bc' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.