Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2022-46908

Published: December 12, 2022Last modified: November 25, 2023

Description

SQLite through 3.40.0, when relying on --safe for execution of an untrusted CLI script, does not properly implement the azProhibitedFunctions protection mechanism, and instead allows UDF functions such as WRITEFILE.

Severity score breakdown

ParameterValue
Base score7.3
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredLOW
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactHIGH
Availability impactLOW
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSsqliteFixed (3.40.1-r0)
StreamsqliteNot affected (3.43.0-r0)

References

ON THIS PAGE