CVE-2023-7104

Name
CVE-2023-7104
Description
A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionReadRecord of the file ext/session/sqlite3session.c of the component make alltest Handler. The manipulation leads to heap-based buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-248999.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cna@vuldb.com https://sqlite.org/forum/forumpost/5bcbf4571c
cna@vuldb.com https://sqlite.org/src/info/0e4e7a05c4204b47
cna@vuldb.com https://vuldb.com/?ctiid.248999
cna@vuldb.com https://vuldb.com/?id.248999
cna@vuldb.com https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D6C2HN4T2S6GYNTAUXLH45LQZHK7QPHP/
cna@vuldb.com https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AYONA2XSNFMXLAW4IHLFI5UVV3QRNG5K/
cna@vuldb.com https://security.netapp.com/advisory/ntap-20240112-0008/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:sqlite:sqlite:*:*:*:*:*:*:*:* sqlite >= None <= 3.43.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
sqlite 3.18-main 3.41.2-r3 Carlo Landmeter <clandmeter@alpinelinux.org> fixed
sqlite 3.17-main 3.40.1-r1 Carlo Landmeter <clandmeter@alpinelinux.org> fixed
sqlite 3.16-main 3.40.1-r1 Carlo Landmeter <clandmeter@alpinelinux.org> fixed