Updated sqlite3 packages fix security vulnerabilities
Publication date: 20 Mar 2024Modification date: 20 Mar 2024
Type: security
Affected Mageia releases : 9
CVE: CVE-2023-2137 , CVE-2023-7104
Description
The updated packages fix security vulnerabilities: Heap buffer overflow in sqlite. (CVE-2023-2137) A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionReadRecord of the file ext/session/sqlite3session.c of the component make alltest Handler. The manipulation leads to heap-based buffer overflow. (CVE-2023-7104)
References
- https://bugs.mageia.org/show_bug.cgi?id=31868
- https://chromereleases.googleblog.com/2023/04/stable-channel-update-for-desktop_18.html
- https://ubuntu.com/security/notices/USN-6566-1
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2137
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-7104
SRPMS
9/core
- sqlite3-3.40.1-1.1.mga9