Bug 1211672 (CVE-2023-32697) - VUL-0: CVE-2023-32697: sqlite-jdbc: Remote code execution when JDBC url is attacker controlled
Summary: VUL-0: CVE-2023-32697: sqlite-jdbc: Remote code execution when JDBC url is at...
Status: RESOLVED FIXED
Alias: CVE-2023-32697
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P5 - None : Major
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/367295/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2023-05-24 06:55 UTC by Thomas Leroy
Modified: 2023-05-24 06:55 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Thomas Leroy 2023-05-24 06:55:21 UTC
CVE-2023-32697

SQLite JDBC is a library for accessing and creating SQLite database files in
Java. Sqlite-jdbc addresses a remote code execution vulnerability via JDBC URL.
This issue impacting versions 3.6.14.1 through 3.41.2.1 and has been fixed in
version 3.41.2.2.


References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-32697
https://www.cve.org/CVERecord?id=CVE-2023-32697
http://www.cvedetails.com/cve/CVE-2023-32697/
https://github.com/xerial/sqlite-jdbc/releases/tag/3.41.2.2
https://github.com/xerial/sqlite-jdbc/security/advisories/GHSA-6phf-6h5g-97j2
Comment 1 Thomas Leroy 2023-05-24 06:55:39 UTC
Already fixed in openSUSE:Factory. Closing