Bug 1212643 (CVE-2023-36191) - VUL-0: CVE-2023-36191: sqlite3: segmentation violation at /sqlite3_aflpp/shell.c
Summary: VUL-0: CVE-2023-36191: sqlite3: segmentation violation at /sqlite3_aflpp/shell.c
Status: RESOLVED INVALID
Alias: CVE-2023-36191
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Minor
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/370250/
Whiteboard: CVSSv3.1:SUSE:CVE-2023-36191:0.0:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2023-06-23 09:35 UTC by Cathy Hu
Modified: 2023-09-25 12:13 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Cathy Hu 2023-06-23 09:35:59 UTC
CVE-2023-36191

sqlite3 v3.40.1 was discovered to contain a segmentation violation at
/sqlite3_aflpp/shell.c.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-36191
https://www.cve.org/CVERecord?id=CVE-2023-36191
https://www.sqlite.org/forum/forumpost/19f55ef73b
Comment 1 Cathy Hu 2023-06-23 09:36:45 UTC
Affected:    
- SUSE:Carwos:1/sqlite3                 3.39.3    
- SUSE:SLE-12-SP1:Update/sqlite3        3.39.3    
- SUSE:SLE-15:Update/sqlite3            3.39.3    
- SUSE:ALP:Source:Standard:1.0/sqlite3  3.41.2    
- openSUSE:Factory/sqlite3              3.42.0    
    
    
Not Affected:    
- SUSE:SLE-12:Update/sqlite2            2.8.17    
- SUSE:SLE-11-SP2:Update/sqlite3        3.7.6.3
Comment 6 Reinhard Max 2023-09-11 14:46:11 UTC
The bug is fixed in version 3.43.0, but upstream didn't bother mentioning it in the change log, because it was no vulnerability and the fix just turned a harmless segfault into a more meaningful error message.

See: https://www.sqlite.org/forum/forumpost/d2415641c876b210
Comment 7 Cathy Hu 2023-09-12 07:24:44 UTC
Thanks, i will file a rejection request at mitre and update the tracking
Comment 8 Cathy Hu 2023-09-25 12:13:04 UTC
rejected, closing