|
Bugzilla – Full Text Bug Listing |
| Summary: | VUL-0: CVE-2023-36191: sqlite3: segmentation violation at /sqlite3_aflpp/shell.c | ||
|---|---|---|---|
| Product: | [Novell Products] SUSE Security Incidents | Reporter: | Cathy Hu <cathy.hu> |
| Component: | Incidents | Assignee: | Security Team bot <security-team> |
| Status: | RESOLVED INVALID | QA Contact: | Security Team bot <security-team> |
| Severity: | Minor | ||
| Priority: | P3 - Medium | CC: | brahmajit.das, max, security-team |
| Version: | unspecified | ||
| Target Milestone: | --- | ||
| Hardware: | Other | ||
| OS: | Other | ||
| URL: | https://smash.suse.de/issue/370250/ | ||
| Whiteboard: | CVSSv3.1:SUSE:CVE-2023-36191:0.0:(AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N) | ||
| Found By: | Security Response Team | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
|
Description
Cathy Hu
2023-06-23 09:35:59 UTC
Affected:
- SUSE:Carwos:1/sqlite3 3.39.3
- SUSE:SLE-12-SP1:Update/sqlite3 3.39.3
- SUSE:SLE-15:Update/sqlite3 3.39.3
- SUSE:ALP:Source:Standard:1.0/sqlite3 3.41.2
- openSUSE:Factory/sqlite3 3.42.0
Not Affected:
- SUSE:SLE-12:Update/sqlite2 2.8.17
- SUSE:SLE-11-SP2:Update/sqlite3 3.7.6.3
The bug is fixed in version 3.43.0, but upstream didn't bother mentioning it in the change log, because it was no vulnerability and the fix just turned a harmless segfault into a more meaningful error message. See: https://www.sqlite.org/forum/forumpost/d2415641c876b210 Thanks, i will file a rejection request at mitre and update the tracking rejected, closing |