Advisories ยป MGASA-2023-0094

Updated sqlite3 packages fix security vulnerability

Publication date: 18 Mar 2023
Modification date: 18 Mar 2023
Type: security
Affected Mageia releases : 8
CVE: CVE-2022-46908

Description

SQLite through 3.40.0, when relying on --safe for execution of an
untrusted CLI script, does not properly implement the
azProhibitedFunctions protection mechanism, and instead allows UDF
functions such as WRITEFILE. (CVE-2022-46908)
                

References

SRPMS

8/core