Lucene search

K
rosalinuxROSA LABROSA-SA-2023-2149
HistoryApr 11, 2023 - 1:56 p.m.

Advisory ROSA-SA-2023-2149

2023-04-1113:56:14
ROSA LAB
abf.rosalinux.ru
12
advisory
sqlite
rosa virtualization
medium
critical
security vulnerabilities

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.011 Low

EPSS

Percentile

84.2%

Software: sqlite 3.26.0
OS: ROSA Virtualization 2.1

package_evr_string: 3.26.0

CVE-ID: CVE-2019-19645
BDU-ID: None
CVE-Crit: MEDIUM
CVE-DESC: Alter.c in SQLite before 3.30.1 allows attackers to trigger infinite recursion using certain types of self-referential views in conjunction with ALTER TABLE statements.
CVE-STATUS: Fixed
CVE-REV: Run the yum update sqlite command to close it

CVE-ID: CVE-2019-19880
BDU-ID: None
CVE-Crit: HIGH
CVE-DESC: ExprListAppendList in window.c in SQLite 3.30.1 allows attackers to initiate invalid pointer dereferencing due to improper handling of constant integer values in ORDER BY sentences of window definitions.
CVE-STATUS: Fixed
CVE-REV: Execute the yum update sqlite command to close it

CVE-ID: CVE-2020-35525
BDU-ID: None
CVE-Crit: HIGH
CVE-DESC: In SQlite 3.31.1, a potential null pointer dereference was detected while processing an INTERSEC request.
CVE-STATUS: Fixed
CVE-REV: Execute the yum update sqlite command to close it

CVE-ID: CVE-2020-35527
BDU-ID: None
CVE-Crit: CRITICAL
CVE-DESC: In SQLite 3.31.1, there is an issue with out-of-bounds access via ALTER TABLE for views that have a nested FROM clause.
CVE-STATUS: Fixed
CVE-REV: Run the yum update sqlite command to close it

CVE-ID: CVE-2022-35737
BDU-ID: None
CVE-Crit: HIGH
CVE-DESC: SQLite from 1.0.12 to 3.39.x to 3.39.2 sometimes allows array boundary overflow if billions of bytes are used in a C API string argument.
CVE-STATUS: Fixed
CVE-REV: Run the yum update sqlite command to close it

OSVersionArchitecturePackageVersionFilename
ROSAanynoarchsqlite< 3.26.0UNKNOWN

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.011 Low

EPSS

Percentile

84.2%