[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250363

 
 

909

 
 

196124

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

RHSA-2020:4442-01 -- Centos sqlite

ID: oval:org.secpod.oval:def:67956Date: (C)2020-12-23   (M)2024-01-29
Class: PATCHFamily: unix




SQLite is a C library that implements an SQL database engine. A large subset of SQL92 is supported. A complete database is stored in a single disk file. The API is designed for convenience and ease of use. Applications that link against SQLite can enjoy the power and flexibility of an SQL database without the administrative hassles of supporting a separate database server. Security Fix: * sqlite: Use-after-free in window function leading to remote code execution * sqlite: Division by zero in whereLoopAddBtreeIndex in sqlite3.c * sqlite: selectExpander in select.c proceeds with WITH stack unwinding even after a parsing error * sqlite: Out-of-bounds read in SELECT with ON/USING clause * sqlite: NULL pointer dereference and segmentation fault because of generated column optimizations * sqlite: Use-after-free in fts3EvalNextRow in ext/fts3/fts3.c * sqlite: Virtual table can be renamed into the name of one of its shadow tables * sqlite: NULL pointer dereference in ext/fts3/fts3_snippet.c via a crafted matchinfo query For more details about the security issue, including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. Additional Changes: For detailed information on changes in this release, see the CentOS 8.3 Release Notes linked from the References section.

Platform:
CentOS 8
Product:
sqlite
Reference:
RHSA-2020:4442-01
CVE-2019-5018
CVE-2019-16168
CVE-2019-20218
CVE-2020-6405
CVE-2020-9327
CVE-2020-13630
CVE-2020-13631
CVE-2020-13632
CVE    8
CVE-2019-5018
CVE-2020-13632
CVE-2020-9327
CVE-2019-20218
...
CPE    2
cpe:/a:sqlite:sqlite
cpe:/o:centos:centos:8

© SecPod Technologies