[Git][security-tracker-team/security-tracker][master] Add CVE-2023-36191 /sqlite3

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Jul 2 07:46:30 BST 2023



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
4447a429 by Salvatore Bonaccorso at 2023-07-02T08:45:59+02:00
Add CVE-2023-36191 /sqlite3

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -974,7 +974,11 @@ CVE-2023-36192 (Sngrep v1.6.0 was discovered to contain a heap buffer overflow v
 	NOTE: https://github.com/irontec/sngrep/issues/438
 	NOTE: https://github.com/irontec/sngrep/commit/ad1daf15c8387bfbb48097c25197bf330d2d98fc
 CVE-2023-36191 (sqlite3 v3.40.1 was discovered to contain a segmentation violation at  ...)
-	TODO: check
+	- sqlite3 <unfixed> (unimportant)
+	- sqlite <removed> (unimportant)
+	NOTE: https://www.sqlite.org/forum/forumpost/19f55ef73b
+	NOTE: https://sqlite.org/src/info/cd24178bbaad4a1d
+	NOTE: NOTE: Negligible security impact
 CVE-2023-35801 (A directory traversal vulnerability in Safe Software FME Server before ...)
 	NOT-FOR-US: Safe Software FME Server
 CVE-2023-35133 (An issue in the logic used to check 0.0.0.0 against the cURL blocked h ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4447a42999dbaeff8e0cd326088c1d4f6e37639d

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4447a42999dbaeff8e0cd326088c1d4f6e37639d
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230702/c7835a5a/attachment.htm>


More information about the debian-security-tracker-commits mailing list