Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2023-7104

Published: December 29, 2023Last modified: November 6, 2024

Description

A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionReadRecord of the file ext/session/sqlite3session.c of the component make alltest Handler. The manipulation leads to heap-based buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-248999.

Severity score breakdown

ParameterValue
Base score7.3
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityLOW
Integrity impactLOW
Availability impactLOW
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSsqliteFixed (3.40.1-r1)
StreamsqliteFixed (3.43.2-r0)
Liberica JDK8jdk-fullFixed (8u432+7)
jre-fullFixed (8u432+7)
11jdk-fullFixed (11.0.24+9)
jre-fullFixed (11.0.24+9)
17jdk-fullFixed (17.0.13+12)
jre-fullFixed (17.0.13+12)
21jdk-fullFixed (21.0.5+11)
jre-fullFixed (21.0.5+11)
Liberica NIK23 (JDK 17)fullFixed (23.0.6+1)
23 (JDK 21)fullFixed (23.1.5+1)

References

Published BELL-SAs

ON THIS PAGE