[ GLSA 202210-40 ] SQLite: Multiple Vulnerabilities

[email protected]
Newsgroups gmane.linux.gentoo.announce
Message-ID <166724789522.9.95891747594669674@90bb6a0775af>
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 202210-40
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                           https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

 Severity: High
    Title: SQLite: Multiple Vulnerabilities
     Date: October 31, 2022
     Bugs: #777990, #863431
       ID: 202210-40

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple vulnerabilities have been found in SQLite, the worst of which
could result in arbitrary code execution.

Background
==========

SQLite is a C library that implements an SQL database engine.

Affected packages
=================

    -------------------------------------------------------------------
     Package              /     Vulnerable     /            Unaffected
    -------------------------------------------------------------------
  1  dev-db/sqlite              < 3.39.2                    >= 3.39.2

Description
===========

Multiple vulnerabilities have been discovered in SQLite. Please review
the CVE identifiers referenced below for details.

Impact
======

Please review the referenced CVE identifiers for details.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All SQLite users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot --verbose ">=dev-db/sqlite-3.39.2"

References
==========

[ 1 ] CVE-2021-20227
      https://nvd.nist.gov/vuln/detail/CVE-2021-20227
[ 2 ] CVE-2022-35737
      https://nvd.nist.gov/vuln/detail/CVE-2022-35737

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

 https://security.gentoo.org/glsa/202210-40

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
[email protected] or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2022 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

https://creativecommons.org/licenses/by-sa/2.5
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEpqTA6ABLMxh/aChGFMQkOaVy+9kFAmNgLxcACgkQFMQkOaVy
+9ln2g/9GRwjLgeox9q+O/8AHdUhWdzkRS4pSXI2XkuOk2cHE1VEqDMf8lJTc5CA
e9fMsBI5wAEnJpPSUvil37ET5t9mHxxcg6Urpumfessr97fhILlOarWkZwz1qh+t
ri+jT3RN8FJ5EVTT7ICR0GUcMofoxCvxlenfTHLQw38gR+akiqAjipBwQ9YapqH6
BQKqDWvqlDxCTTAgeZg6UO4N+VwGRV6/yOTNygTjVCPTPaBIod/tT5fCPhwvdC/X
cDfbQhc1FpMaOAgxggz3nU+6Fu3DWstK9WDauG1YlWIU6KVp0TxZwDxmHH7Aq7P7
1wKYj8apOJ6ZD/43H0EetLlB3Md9sg5789hCAvs+uK3NCfBeXIrh4EVwrdZgTBlZ
+jaRKbDHImPVHiS40SZMNmqbAOlrF+8YeXU8lBo7yXpc7RvS50dv0BWHAiY9rEnK
7a7sfEZNTt52BsNY2VJL5hjCclibBaIdbXqlq9QfqKWXUKYnEsDB1Uq0tK9QrnTM
JO/oETVIL1wP7/SDcSL9WZlnFs4aCy4s7rmOEdiqVRYICPdDpmn8tNAUB+NIwXdy
B8Q+XK2/0IXrzjLmTCcssNzqCjBhGJ5nzqbDXHnMIIoAI/5kyH9aF0/7uGu7ok13
ivI/PCq5qffEGAFNRARuqkWaOBxP12LUyNKy4uOU9nZmlO/HqPA=
=85fl
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.