Oval Definition:oval:org.opensuse.security:def:55250
Revision Date:2021-09-23Version:1
Title:Security update for sqlite3 (Important)
Description:

This update for sqlite3 fixes the following issues:

sqlite3 is sync version 3.36.0 from Factory (jsc#SLE-16032).

The following CVEs have been fixed in upstream releases up to this point, but were not mentioned in the change log so far:

bsc#1173641, CVE-2020-15358: heap-based buffer overflow in multiSelectOrderBy due to mishandling of query-flattener optimization * bsc#1164719, CVE-2020-9327: NULL pointer dereference and segmentation fault because of generated column optimizations in isAuxiliaryVtabOperator * bsc#1160439, CVE-2019-20218: selectExpander in select.c proceeds with WITH stack unwinding even after a parsing error * bsc#1160438, CVE-2019-19959: memory-management error via ext/misc/zipfile.c involving embedded '\0' input * bsc#1160309, CVE-2019-19923: improper handling of certain uses of SELECT DISTINCT in flattenSubquery may lead to null pointer dereference * bsc#1159850, CVE-2019-19924: improper error handling in sqlite3WindowRewrite() * bsc#1159847, CVE-2019-19925: improper handling of NULL pathname during an update of a ZIP archive * bsc#1159715, CVE-2019-19926: improper handling of certain errors during parsing multiSelect in select.c * bsc#1159491, CVE-2019-19880: exprListAppendList in window.c allows attackers to trigger an invalid pointer dereference * bsc#1158960, CVE-2019-19603: during handling of CREATE TABLE and CREATE VIEW statements, does not consider confusion with a shadow table name * bsc#1158959, CVE-2019-19646: pragma.c mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns * bsc#1158958, CVE-2019-19645: alter.c allows attackers to trigger infinite recursion via certain types of self-referential views in conjunction with ALTER TABLE statements * bsc#1158812, CVE-2019-19317: lookupName in resolve.c omits bits from the colUsed bitmask in the case of a generated column, which allows attackers to cause a denial of service * bsc#1157818, CVE-2019-19244: sqlite3,sqlite2,sqlite: The function sqlite3Select in select.c allows a crash if a sub-select uses both DISTINCT and window functions, and also has certain ORDER BY usage * bsc#928701, CVE-2015-3415: sqlite3VdbeExec comparison operator vulnerability * bsc#928700, CVE-2015-3414: sqlite3,sqlite2: dequoting of collation-sequence names * CVE-2020-13434 bsc#1172115: integer overflow in sqlite3_str_vappendf * CVE-2020-13630 bsc#1172234: use-after-free in fts3EvalNextRow * CVE-2020-13631 bsc#1172236: virtual table allowed to be renamed to one of its shadow tables * CVE-2020-13632 bsc#1172240: NULL pointer dereference via crafted matchinfo() query * CVE-2020-13435: Malicious SQL statements could have crashed the process that is running SQLite (bsc#1172091)
Family:unixClass:patch
Status:Reference(s):1035442
1052825
1062571
1062760
1064947
1065766
1070130
1072887
1073973
1076500
1081925
1100408
1106222
1110910
1111006
1111010
1111013
1114422
1117993
1130721
1132256
1132678
1157818
1158812
1158958
1158959
1158960
1159491
1159715
1159847
1159850
1160309
1160438
1160439
1164719
1172091
1172115
1172234
1172236
1172240
1173641
774666
815451
821664
849019
917427
928700
928701
941234
946148
952099
952539
954126
954519
955493
955609
956631
957812
969820
972907
983232
983234
983253
983259
983292
983305
983308
983521
983523
983527
983533
983739
983746
983752
983774
983794
983796
983799
983803
984014
984018
984023
984028
984032
984035
984135
984137
984142
984144
984145
984149
984150
984160
984166
984172
984179
984181
984183
984184
984185
984186
984187
984191
984193
984370
984372
984373
984374
984375
984379
984394
984398
984400
984401
984404
984406
984408
984409
984427
984433
984436
985442
985448
985451
985456
985460
986608
986609
CVE-2011-3970
CVE-2012-2417
CVE-2012-2825
CVE-2012-6139
CVE-2013-1445
CVE-2013-1981
CVE-2013-1997
CVE-2013-2004
CVE-2014-3564
CVE-2014-9805
CVE-2014-9806
CVE-2014-9807
CVE-2014-9808
CVE-2014-9809
CVE-2014-9810
CVE-2014-9811
CVE-2014-9812
CVE-2014-9813
CVE-2014-9814
CVE-2014-9815
CVE-2014-9816
CVE-2014-9817
CVE-2014-9818
CVE-2014-9819
CVE-2014-9820
CVE-2014-9821
CVE-2014-9822
CVE-2014-9823
CVE-2014-9824
CVE-2014-9825
CVE-2014-9826
CVE-2014-9828
CVE-2014-9829
CVE-2014-9830
CVE-2014-9831
CVE-2014-9832
CVE-2014-9833
CVE-2014-9834
CVE-2014-9835
CVE-2014-9836
CVE-2014-9837
CVE-2014-9838
CVE-2014-9839
CVE-2014-9840
CVE-2014-9841
CVE-2014-9842
CVE-2014-9843
CVE-2014-9844
CVE-2014-9845
CVE-2014-9846
CVE-2014-9847
CVE-2014-9848
CVE-2014-9849
CVE-2014-9850
CVE-2014-9851
CVE-2014-9852
CVE-2014-9853
CVE-2014-9854
CVE-2015-3195
CVE-2015-3414
CVE-2015-3415
CVE-2015-5180
CVE-2015-8370
CVE-2015-8894
CVE-2015-8895
CVE-2015-8896
CVE-2015-8897
CVE-2015-8898
CVE-2015-8900
CVE-2015-8901
CVE-2015-8902
CVE-2015-8903
CVE-2016-1544
CVE-2016-2774
CVE-2016-4562
CVE-2016-4563
CVE-2016-4564
CVE-2016-5687
CVE-2016-5688
CVE-2016-5689
CVE-2016-5690
CVE-2016-5691
CVE-2016-5841
CVE-2016-5842
CVE-2016-6153
CVE-2017-10989
CVE-2017-2518
CVE-2017-5974
CVE-2017-5975
CVE-2017-5976
CVE-2017-5977
CVE-2017-5978
CVE-2017-5979
CVE-2017-5981
CVE-2018-1058
CVE-2018-10839
CVE-2018-15746
CVE-2018-17828
CVE-2018-17958
CVE-2018-17962
CVE-2018-17963
CVE-2018-18849
CVE-2018-20346
CVE-2018-5748
CVE-2018-6381
CVE-2018-6484
CVE-2018-6540
CVE-2018-6542
CVE-2018-7725
CVE-2018-7726
CVE-2018-8740
CVE-2019-11070
CVE-2019-16168
CVE-2019-1787
CVE-2019-1788
CVE-2019-1789
CVE-2019-19244
CVE-2019-19317
CVE-2019-19603
CVE-2019-19645
CVE-2019-19646
CVE-2019-19880
CVE-2019-19923
CVE-2019-19924
CVE-2019-19925
CVE-2019-19926
CVE-2019-19959
CVE-2019-20218
CVE-2019-6201
CVE-2019-6251
CVE-2019-7285
CVE-2019-7292
CVE-2019-8457
CVE-2019-8503
CVE-2019-8506
CVE-2019-8515
CVE-2019-8524
CVE-2019-8535
CVE-2019-8536
CVE-2019-8544
CVE-2019-8551
CVE-2019-8558
CVE-2019-8559
CVE-2019-8563
CVE-2020-13434
CVE-2020-13435
CVE-2020-13630
CVE-2020-13631
CVE-2020-13632
CVE-2020-15358
CVE-2020-9327
SUSE-SU-2015:2251-1
SUSE-SU-2015:2387-1
SUSE-SU-2016:1784-1
SUSE-SU-2016:1791-1
SUSE-SU-2018:0279-1
SUSE-SU-2018:0756-1
SUSE-SU-2018:4129-1
SUSE-SU-2019:0897-1
SUSE-SU-2019:1155-1
SUSE-SU-2019:1716-1
SUSE-SU-2021:3215-1
Platform(s):openSUSE Leap 15.0
openSUSE Leap 15.1
SUSE Linux Enterprise Desktop 11 SP2
SUSE Linux Enterprise Desktop 11 SP3
SUSE Linux Enterprise Desktop 11 SP4
SUSE Linux Enterprise Desktop 12 SP3
SUSE Linux Enterprise Desktop 12 SP4
SUSE Linux Enterprise Server 12 SP1
SUSE Linux Enterprise Server 12 SP1-LTSS
SUSE Linux Enterprise Server 12 SP2
SUSE Linux Enterprise Server 12 SP2-BCL
SUSE Linux Enterprise Server 12 SP2-ESPOS
SUSE Linux Enterprise Server 12 SP2-LTSS
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP3-BCL
SUSE Linux Enterprise Server 12 SP3-ESPOS
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP3-TERADATA
SUSE Linux Enterprise Server 12 SP4
SUSE OpenStack Cloud 6
SUSE OpenStack Cloud 7
Product(s):
Definition Synopsis
  • openSUSE Leap 15.0 is installed
  • AND Package Information
  • bash-4.4-lp150.7 is installed
  • OR bash-doc-4.4-lp150.7 is installed
  • OR bash-lang-4.4-lp150.7 is installed
  • OR libreadline7-7.0-lp150.7 is installed
  • OR readline-doc-7.0-lp150.7 is installed
  • Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • SDL2-2.0.8-lp151.4.3 is installed
  • OR libSDL2-2_0-0-2.0.8-lp151.4.3 is installed
  • OR libSDL2-2_0-0-32bit-2.0.8-lp151.4.3 is installed
  • OR libSDL2-devel-2.0.8-lp151.4.3 is installed
  • OR libSDL2-devel-32bit-2.0.8-lp151.4.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 11 SP2 is installed
  • AND Package Information
  • xorg-x11-libX11-7.4-5.11.11 is installed
  • OR xorg-x11-libX11-32bit-7.4-5.11.11 is installed
  • OR xorg-x11-libX11-devel-7.4-5.11.11 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 11 SP3 is installed
  • AND Package Information
  • libxslt-1.1.24-19.23 is installed
  • OR libxslt-32bit-1.1.24-19.23 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 11 SP4 is installed
  • AND Package Information
  • compat-openssl097g-0.9.7g-146.22.36 is installed
  • OR compat-openssl097g-32bit-0.9.7g-146.22.36 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP3 is installed
  • AND Package Information
  • libvirt-3.3.0-5.13 is installed
  • OR libvirt-admin-3.3.0-5.13 is installed
  • OR libvirt-client-3.3.0-5.13 is installed
  • OR libvirt-daemon-3.3.0-5.13 is installed
  • OR libvirt-daemon-config-network-3.3.0-5.13 is installed
  • OR libvirt-daemon-config-nwfilter-3.3.0-5.13 is installed
  • OR libvirt-daemon-driver-interface-3.3.0-5.13 is installed
  • OR libvirt-daemon-driver-libxl-3.3.0-5.13 is installed
  • OR libvirt-daemon-driver-lxc-3.3.0-5.13 is installed
  • OR libvirt-daemon-driver-network-3.3.0-5.13 is installed
  • OR libvirt-daemon-driver-nodedev-3.3.0-5.13 is installed
  • OR libvirt-daemon-driver-nwfilter-3.3.0-5.13 is installed
  • OR libvirt-daemon-driver-qemu-3.3.0-5.13 is installed
  • OR libvirt-daemon-driver-secret-3.3.0-5.13 is installed
  • OR libvirt-daemon-driver-storage-3.3.0-5.13 is installed
  • OR libvirt-daemon-driver-storage-core-3.3.0-5.13 is installed
  • OR libvirt-daemon-driver-storage-disk-3.3.0-5.13 is installed
  • OR libvirt-daemon-driver-storage-iscsi-3.3.0-5.13 is installed
  • OR libvirt-daemon-driver-storage-logical-3.3.0-5.13 is installed
  • OR libvirt-daemon-driver-storage-mpath-3.3.0-5.13 is installed
  • OR libvirt-daemon-driver-storage-rbd-3.3.0-5.13 is installed
  • OR libvirt-daemon-driver-storage-scsi-3.3.0-5.13 is installed
  • OR libvirt-daemon-lxc-3.3.0-5.13 is installed
  • OR libvirt-daemon-qemu-3.3.0-5.13 is installed
  • OR libvirt-daemon-xen-3.3.0-5.13 is installed
  • OR libvirt-doc-3.3.0-5.13 is installed
  • OR libvirt-libs-3.3.0-5.13 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP4 is installed
  • AND Package Information
  • libnghttp2-14-1.7.1-1 is installed
  • OR libnghttp2-14-32bit-1.7.1-1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP1 is installed
  • AND Package Information
  • gpgme-1.5.1-1 is installed
  • OR libgpgme11-1.5.1-1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP1-LTSS is installed
  • AND Package Information
  • kgraft-patch-3_12_62-60_64_8-default-9-3 is installed
  • OR kgraft-patch-3_12_62-60_64_8-xen-9-3 is installed
  • OR kgraft-patch-SLE12-SP1_Update_8-9-3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2 is installed
  • AND Package Information
  • apache-commons-daemon-1.0.15-4 is installed
  • OR apache-commons-daemon-javadoc-1.0.15-4 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-BCL is installed
  • AND Package Information
  • libsqlite3-0-3.36.0-9.18.1 is installed
  • OR libsqlite3-0-32bit-3.36.0-9.18.1 is installed
  • OR sqlite3-3.36.0-9.18.1 is installed
  • OR sqlite3-devel-3.36.0-9.18.1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-ESPOS is installed
  • AND ucode-intel-20191112a-13.56 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-LTSS is installed
  • AND Package Information
  • kgraft-patch-4_4_114-92_64-default-5-2 is installed
  • OR kgraft-patch-SLE12-SP2_Update_18-5-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND Package Information
  • evince-3.20.1-5 is installed
  • OR evince-browser-plugin-3.20.1-5 is installed
  • OR evince-lang-3.20.1-5 is installed
  • OR evince-plugin-djvudocument-3.20.1-5 is installed
  • OR evince-plugin-dvidocument-3.20.1-5 is installed
  • OR evince-plugin-pdfdocument-3.20.1-5 is installed
  • OR evince-plugin-psdocument-3.20.1-5 is installed
  • OR evince-plugin-tiffdocument-3.20.1-5 is installed
  • OR evince-plugin-xpsdocument-3.20.1-5 is installed
  • OR libevdocument3-4-3.20.1-5 is installed
  • OR libevview3-3-3.20.1-5 is installed
  • OR nautilus-evince-3.20.1-5 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-BCL is installed
  • AND Package Information
  • strongswan-5.1.3-26.13 is installed
  • OR strongswan-doc-5.1.3-26.13 is installed
  • OR strongswan-hmac-5.1.3-26.13 is installed
  • OR strongswan-ipsec-5.1.3-26.13 is installed
  • OR strongswan-libs0-5.1.3-26.13 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-ESPOS is installed
  • AND Package Information
  • libsolv-0.6.36-2.27.19 is installed
  • OR libsolv-tools-0.6.36-2.27.19 is installed
  • OR libzypp-16.20.2-27.60 is installed
  • OR perl-solv-0.6.36-2.27.19 is installed
  • OR python-solv-0.6.36-2.27.19 is installed
  • OR zypper-1.13.54-18.40 is installed
  • OR zypper-log-1.13.54-18.40 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND Package Information
  • kgraft-patch-4_4_162-94_72-default-5-2 is installed
  • OR kgraft-patch-SLE12-SP3_Update_22-5-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND Package Information
  • ImageMagick-6.8.8.1-71.93 is installed
  • OR libMagickCore-6_Q16-1-6.8.8.1-71.93 is installed
  • OR libMagickWand-6_Q16-1-6.8.8.1-71.93 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND Package Information
  • cron-4.2-58 is installed
  • OR cronie-1.4.11-58 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 6 is installed
  • AND python-pycrypto-2.6.1-2 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 7 is installed
  • AND Package Information
  • perl-5.18.2-12.14 is installed
  • OR perl-32bit-5.18.2-12.14 is installed
  • OR perl-base-5.18.2-12.14 is installed
  • OR perl-doc-5.18.2-12.14 is installed
  • BACK