ALT-PU-2019-1971-1
Closed vulnerabilities
BDU:2019-03778
Уязвимость компонентов ext/fts5/fts5_hash.c и ext/fts5/fts5_index.c системы управления базами данных SQLite, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2019-03779
Уязвимость функции fts5HashEntrySort в sqlite3.c системы управления базами данных SQLite, позволяющая нарушителю раскрыть защищаемую информацию
BDU:2019-03785
Уязвимость функции rtreenode() системы управления базами данных SQLite, позволяющая нарушителю вызвать отказ в обслуживании, выполнить произвольный код или раскрыть защищаемую информацию
Modified: 2024-11-21
CVE-2019-8457
SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree tables.
- openSUSE-SU-2019:1645
- https://kc.mcafee.com/corporate/index?page=content&id=SB10365
- FEDORA-2019-3377813d18
- FEDORA-2019-02b81266b7
- https://security.netapp.com/advisory/ntap-20190606-0002/
- USN-4004-1
- USN-4004-2
- USN-4019-1
- USN-4019-2
- https://www.oracle.com/security-alerts/cpuapr2020.html
- https://www.oracle.com/security-alerts/cpujan2020.html
- https://www.oracle.com/security-alerts/cpujul2020.html
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
- https://www.sqlite.org/releaselog/3_28_0.html
- https://www.sqlite.org/src/info/90acdbfce9c08858
- openSUSE-SU-2019:1645
- https://www.sqlite.org/src/info/90acdbfce9c08858
- https://www.sqlite.org/releaselog/3_28_0.html
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
- https://www.oracle.com/security-alerts/cpujul2020.html
- https://www.oracle.com/security-alerts/cpujan2020.html
- https://www.oracle.com/security-alerts/cpuapr2020.html
- USN-4019-2
- USN-4019-1
- USN-4004-2
- USN-4004-1
- https://security.netapp.com/advisory/ntap-20190606-0002/
- FEDORA-2019-02b81266b7
- FEDORA-2019-3377813d18
- https://kc.mcafee.com/corporate/index?page=content&id=SB10365
Modified: 2024-11-21
CVE-2019-9936
In SQLite 3.27.2, running fts5 prefix queries inside a transaction could trigger a heap-based buffer over-read in fts5HashEntrySort in sqlite3.c, which may lead to an information leak. This is related to ext/fts5/fts5_hash.c.
- openSUSE-SU-2019:1372
- 107562
- [debian-lts-announce] 20200822 [SECURITY] [DLA 2340-1] sqlite3 security update
- FEDORA-2019-8641591b3c
- FEDORA-2019-a01751837d
- GLSA-201908-09
- https://security.netapp.com/advisory/ntap-20190416-0005/
- https://sqlite.org/src/info/b3fa58dd7403dbd4
- USN-4019-1
- https://www.mail-archive.com/sqlite-users%40mailinglists.sqlite.org/msg114382.html
- https://www.mail-archive.com/sqlite-users%40mailinglists.sqlite.org/msg114394.html
- https://www.oracle.com/security-alerts/cpujan2020.html
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
- openSUSE-SU-2019:1372
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
- https://www.oracle.com/security-alerts/cpujan2020.html
- https://www.mail-archive.com/sqlite-users%40mailinglists.sqlite.org/msg114394.html
- https://www.mail-archive.com/sqlite-users%40mailinglists.sqlite.org/msg114382.html
- USN-4019-1
- https://sqlite.org/src/info/b3fa58dd7403dbd4
- https://security.netapp.com/advisory/ntap-20190416-0005/
- GLSA-201908-09
- FEDORA-2019-a01751837d
- FEDORA-2019-8641591b3c
- [debian-lts-announce] 20200822 [SECURITY] [DLA 2340-1] sqlite3 security update
- 107562
Modified: 2024-11-21
CVE-2019-9937
In SQLite 3.27.2, interleaving reads and writes in a single transaction with an fts5 virtual table will lead to a NULL Pointer Dereference in fts5ChunkIterate in sqlite3.c. This is related to ext/fts5/fts5_hash.c and ext/fts5/fts5_index.c.
- openSUSE-SU-2019:1372
- 107562
- [debian-lts-announce] 20200822 [SECURITY] [DLA 2340-1] sqlite3 security update
- FEDORA-2019-8641591b3c
- FEDORA-2019-a01751837d
- GLSA-201908-09
- https://security.netapp.com/advisory/ntap-20190416-0005/
- https://sqlite.org/src/info/45c73deb440496e8
- USN-4019-1
- https://www.mail-archive.com/sqlite-users%40mailinglists.sqlite.org/msg114383.html
- https://www.mail-archive.com/sqlite-users%40mailinglists.sqlite.org/msg114393.html
- https://www.oracle.com/security-alerts/cpujan2020.html
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
- openSUSE-SU-2019:1372
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
- https://www.oracle.com/security-alerts/cpujan2020.html
- https://www.mail-archive.com/sqlite-users%40mailinglists.sqlite.org/msg114393.html
- https://www.mail-archive.com/sqlite-users%40mailinglists.sqlite.org/msg114383.html
- USN-4019-1
- https://sqlite.org/src/info/45c73deb440496e8
- https://security.netapp.com/advisory/ntap-20190416-0005/
- GLSA-201908-09
- FEDORA-2019-a01751837d
- FEDORA-2019-8641591b3c
- [debian-lts-announce] 20200822 [SECURITY] [DLA 2340-1] sqlite3 security update
- 107562