An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for sqliteodbc ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:0628-1 Rating: important References: #1171041 Cross-References: CVE-2020-12050 Affected Products: openSUSE Leap 15.1 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for sqliteodbc fixes the following issues: Security issue fixed: - CVE-2020-12050: Fixed a privilege escalation vulnerability (boo#1171041). Non-security issues fixed: - Update to version 0.9996 * update to SQLite 3.22.0 * fixes in handling DDL in SQLExecDirect() et.al., thanks Andre Mikulec for testing * cleanup utf8/unicode conversion functions Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2020-628=1 Package List: - openSUSE Leap 15.1 (x86_64): sqliteodbc-0.9996-lp151.3.3.1 sqliteodbc-debuginfo-0.9996-lp151.3.3.1 sqliteodbc-debugsource-0.9996-lp151.3.3.1 sqliteodbc-doc-0.9996-lp151.3.3.1 References: https://www.suse.com/security/cve/CVE-2020-12050.html https://bugzilla.suse.com/1171041 -- . openSUSE releases critical patch for sqliteodbc to address security flaw allowing privilege escalation. Discover more details.. sqliteodbc Fixes, openSUSE Updates, Important Security Advisory. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for sqliteodbc ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:0612-1 Rating: important References: #1171041 Cross-References: CVE-2020-12050 Affected Products: openSUSE Backports SLE-15-SP1 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for sqliteodbc fixes the following issues: Security issue fixed: - CVE-2020-12050: Fixed a privilege escalation vulnerability (boo#1171041). Non-security issues fixed: - Update to version 0.9996 * update to SQLite 3.22.0 * fixes in handling DDL in SQLExecDirect() et.al., thanks Andre Mikulec for testing * cleanup utf8/unicode conversion functions Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP1: zypper in -t patch openSUSE-2020-612=1 Package List: - openSUSE Backports SLE-15-SP1 (aarch64 ppc64le s390x x86_64): sqliteodbc-0.9996-bp151.4.3.1 sqliteodbc-doc-0.9996-bp151.4.3.1 References: https://www.suse.com/security/cve/CVE-2020-12050.html https://bugzilla.suse.com/1171041 -- . A crucial security update for openSUSE has been released to fix a vulnerability in sqliteodbc. Users must act quickly to protect their systems from exploitation. OpenSUSE Update, SQLiteODBC Security Fix, Privilege Escalation. . Severity: Important. LinuxSecurity.com Team
Fix CVE-2020-12050 (use mktemp(1) for temp. file name creation). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-df7c647fa3 2020-05-01 04:04:10.484712 --------------------------------------------------------------------------------Name : sqliteodbc Product : Fedora 32 Version : 0.9996 Release : 6.fc32 URL : http://www.ch-werner.de/sqliteodbc/ Summary : SQLite ODBC Driver Description : ODBC driver for SQLite interfacing SQLite 2.x and/or 3.x using the unixODBC or iODBC driver managers. For more information refer to: - https://sqlite.org/ - SQLite engine - https://www.unixodbc.org/ - unixODBC Driver Manager - https://www.iodbc.org/dataspace/doc/iodbc/wiki/iodbcWiki/WelcomeVisitors - iODBC Driver Manager --------------------------------------------------------------------------------Update Information: Fix CVE-2020-12050 (use mktemp(1) for temp. file name creation) --------------------------------------------------------------------------------ChangeLog: * Wed Apr 22 2020 Damian Wrobel - 0.9996-6 - Fix CVE-2020-12050 (use mktemp(1) for temp. file name creation) - Use absolute paths for binaries --------------------------------------------------------------------------------References: [ 1 ] Bug #1825762 - Packaging vulnerability in sqliteODBC exposing to local privilege escalation to root https://bugzilla.redhat.com/show_bug.cgi?id=1825762 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-df7c647fa3' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Fix CVE-2020-12050 (use mktemp(1) for temp. file name creation). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-c98c7da2f6 2020-04-30 03:42:10.988792 --------------------------------------------------------------------------------Name : sqliteodbc Product : Fedora 31 Version : 0.9996 Release : 6.fc31 URL : http://www.ch-werner.de/sqliteodbc/ Summary : SQLite ODBC Driver Description : ODBC driver for SQLite interfacing SQLite 2.x and/or 3.x using the unixODBC or iODBC driver managers. For more information refer to: - https://sqlite.org/ - SQLite engine - https://www.unixodbc.org/ - unixODBC Driver Manager - https://www.iodbc.org/dataspace/doc/iodbc/wiki/iodbcWiki/WelcomeVisitors - iODBC Driver Manager --------------------------------------------------------------------------------Update Information: Fix CVE-2020-12050 (use mktemp(1) for temp. file name creation) --------------------------------------------------------------------------------ChangeLog: * Wed Apr 22 2020 Damian Wrobel - 0.9996-6 - Fix CVE-2020-12050 (use mktemp(1) for temp. file name creation) - Use absolute paths for binaries --------------------------------------------------------------------------------References: [ 1 ] Bug #1825762 - Packaging vulnerability in sqliteODBC exposing to local privilege escalation to root https://bugzilla.redhat.com/show_bug.cgi?id=1825762 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-c98c7da2f6' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Fix CVE-2020-12050 (use mktemp(1) for temp. file name creation). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-1e85425a52 2020-04-30 02:50:26.526819 --------------------------------------------------------------------------------Name : sqliteodbc Product : Fedora 30 Version : 0.9996 Release : 4.fc30 URL : http://www.ch-werner.de/sqliteodbc/ Summary : SQLite ODBC Driver Description : ODBC driver for SQLite interfacing SQLite 2.x and/or 3.x using the unixODBC or iODBC driver managers. For more information refer to: - https://sqlite.org/ - SQLite engine - https://www.unixodbc.org/ - unixODBC Driver Manager - https://www.iodbc.org/dataspace/doc/iodbc/wiki/iodbcWiki/WelcomeVisitors - iODBC Driver Manager --------------------------------------------------------------------------------Update Information: Fix CVE-2020-12050 (use mktemp(1) for temp. file name creation) --------------------------------------------------------------------------------ChangeLog: * Wed Apr 22 2020 Damian Wrobel - 0.9996-4 - Fix CVE-2020-12050 (use mktemp(1) for temp. file name creation) - Use absolute paths for binaries --------------------------------------------------------------------------------References: [ 1 ] Bug #1825762 - Packaging vulnerability in sqliteODBC exposing to local privilege escalation to root https://bugzilla.redhat.com/show_bug.cgi?id=1825762 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-1e85425a52' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.