Bugzilla – Bug 1212643
VUL-0: CVE-2023-36191: sqlite3: segmentation violation at /sqlite3_aflpp/shell.c
Last modified: 2023-09-25 12:13:04 UTC
CVE-2023-36191 sqlite3 v3.40.1 was discovered to contain a segmentation violation at /sqlite3_aflpp/shell.c. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-36191 https://www.cve.org/CVERecord?id=CVE-2023-36191 https://www.sqlite.org/forum/forumpost/19f55ef73b
Affected: - SUSE:Carwos:1/sqlite3 3.39.3 - SUSE:SLE-12-SP1:Update/sqlite3 3.39.3 - SUSE:SLE-15:Update/sqlite3 3.39.3 - SUSE:ALP:Source:Standard:1.0/sqlite3 3.41.2 - openSUSE:Factory/sqlite3 3.42.0 Not Affected: - SUSE:SLE-12:Update/sqlite2 2.8.17 - SUSE:SLE-11-SP2:Update/sqlite3 3.7.6.3
The bug is fixed in version 3.43.0, but upstream didn't bother mentioning it in the change log, because it was no vulnerability and the fix just turned a harmless segfault into a more meaningful error message. See: https://www.sqlite.org/forum/forumpost/d2415641c876b210
Thanks, i will file a rejection request at mitre and update the tracking
rejected, closing