Advisories ยป MGASA-2024-0073

Updated sqlite3 packages fix security vulnerabilities

Publication date: 20 Mar 2024
Modification date: 20 Mar 2024
Type: security
Affected Mageia releases : 9
CVE: CVE-2023-2137 , CVE-2023-7104

Description

The updated packages fix security vulnerabilities:
Heap buffer overflow in sqlite. (CVE-2023-2137)
A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified
as critical. This issue affects the function sessionReadRecord of the
file ext/session/sqlite3session.c of the component make alltest Handler.
The manipulation leads to heap-based buffer overflow. (CVE-2023-7104)
                

References

SRPMS

9/core