CVE-2023-7104

Name
CVE-2023-7104
Description
A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionReadRecord of the file ext/session/sqlite3session.c of the component make alltest Handler. The manipulation leads to heap-based buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-248999.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cna@vuldb.com https://sqlite.org/forum/forumpost/5bcbf4571c
cna@vuldb.com https://sqlite.org/src/info/0e4e7a05c4204b47
cna@vuldb.com https://vuldb.com/?ctiid.248999
cna@vuldb.com https://vuldb.com/?id.248999
cna@vuldb.com https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D6C2HN4T2S6GYNTAUXLH45LQZHK7QPHP/
cna@vuldb.com https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AYONA2XSNFMXLAW4IHLFI5UVV3QRNG5K/
cna@vuldb.com https://security.netapp.com/advisory/ntap-20240112-0008/
af854a3a-2127-422b-91ae-364da2661108 https://lists.debian.org/debian-lts-announce/2024/09/msg00050.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:sqlite:sqlite:*:*:*:*:*:*:*:* sqlite >= None <= 3.43.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
sqlite edge-main 3.36.0-r0 Carlo Landmeter <clandmeter@alpinelinux.org> possibly vulnerable
sqlite edge-main 3.34.1-r0 None possibly vulnerable
sqlite edge-main 3.32.1-r0 None possibly vulnerable
sqlite edge-main 3.30.1-r3 None possibly vulnerable
sqlite edge-main 3.30.1-r1 None possibly vulnerable
sqlite edge-main 3.28.0-r0 None possibly vulnerable
sqlite 3.22-main 3.34.1-r0 None possibly vulnerable
sqlite 3.22-main 3.32.1-r0 None possibly vulnerable
sqlite 3.22-main 3.30.1-r3 None possibly vulnerable
sqlite 3.22-main 3.30.1-r1 None possibly vulnerable
sqlite 3.22-main 3.28.0-r0 None possibly vulnerable
sqlite 3.21-main 3.34.1-r0 None possibly vulnerable
sqlite 3.21-main 3.32.1-r0 None possibly vulnerable
sqlite 3.21-main 3.30.1-r3 None possibly vulnerable
sqlite 3.21-main 3.30.1-r1 None possibly vulnerable
sqlite 3.21-main 3.28.0-r0 None possibly vulnerable
sqlite 3.20-main 3.34.1-r0 None possibly vulnerable
sqlite 3.20-main 3.32.1-r0 None possibly vulnerable
sqlite 3.20-main 3.30.1-r3 None possibly vulnerable
sqlite 3.20-main 3.30.1-r1 None possibly vulnerable
sqlite 3.20-main 3.28.0-r0 None possibly vulnerable
sqlite 3.19-main 3.34.1-r0 None possibly vulnerable
sqlite 3.19-main 3.32.1-r0 None possibly vulnerable
sqlite 3.19-main 3.30.1-r3 None possibly vulnerable
sqlite 3.19-main 3.30.1-r1 None possibly vulnerable
sqlite 3.19-main 3.28.0-r0 None possibly vulnerable
sqlite 3.18-main 3.41.2-r3 Carlo Landmeter <clandmeter@alpinelinux.org> fixed
sqlite 3.17-main 3.40.1-r1 Carlo Landmeter <clandmeter@alpinelinux.org> fixed
qt6-qtwebengine edge-community 6.6.3-r1 Bart Ribbers <bribbers@disroot.org> fixed
qt6-qtwebengine 3.22-community 6.6.3-r1 None fixed
qt6-qtwebengine 3.21-community 6.6.3-r1 None fixed
qt6-qtwebengine 3.20-community 6.6.3-r1 None fixed
qt6-qtwebengine 3.19-community 6.6.1-r9 Bart Ribbers <bribbers@disroot.org> fixed
qt5-qtwebengine edge-community 5.15.16-r7 Bart Ribbers <bribbers@disroot.org> fixed
qt5-qtwebengine 3.22-community 5.15.16-r7 None fixed
qt5-qtwebengine 3.21-community 5.15.16-r7 None fixed
qt5-qtwebengine 3.20-community 5.15.16-r7 None fixed
qt5-qtwebengine 3.19-community 5.15.16-r5 Bart Ribbers <bribbers@disroot.org> fixed