Oval Definition:oval:org.opensuse.security:def:58018
Revision Date:2021-09-23Version:1
Title:Security update for sqlite3 (Important)
Description:

This update for sqlite3 fixes the following issues:

sqlite3 is sync version 3.36.0 from Factory (jsc#SLE-16032).

The following CVEs have been fixed in upstream releases up to this point, but were not mentioned in the change log so far:

bsc#1173641, CVE-2020-15358: heap-based buffer overflow in multiSelectOrderBy due to mishandling of query-flattener optimization * bsc#1164719, CVE-2020-9327: NULL pointer dereference and segmentation fault because of generated column optimizations in isAuxiliaryVtabOperator * bsc#1160439, CVE-2019-20218: selectExpander in select.c proceeds with WITH stack unwinding even after a parsing error * bsc#1160438, CVE-2019-19959: memory-management error via ext/misc/zipfile.c involving embedded '\0' input * bsc#1160309, CVE-2019-19923: improper handling of certain uses of SELECT DISTINCT in flattenSubquery may lead to null pointer dereference * bsc#1159850, CVE-2019-19924: improper error handling in sqlite3WindowRewrite() * bsc#1159847, CVE-2019-19925: improper handling of NULL pathname during an update of a ZIP archive * bsc#1159715, CVE-2019-19926: improper handling of certain errors during parsing multiSelect in select.c * bsc#1159491, CVE-2019-19880: exprListAppendList in window.c allows attackers to trigger an invalid pointer dereference * bsc#1158960, CVE-2019-19603: during handling of CREATE TABLE and CREATE VIEW statements, does not consider confusion with a shadow table name * bsc#1158959, CVE-2019-19646: pragma.c mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns * bsc#1158958, CVE-2019-19645: alter.c allows attackers to trigger infinite recursion via certain types of self-referential views in conjunction with ALTER TABLE statements * bsc#1158812, CVE-2019-19317: lookupName in resolve.c omits bits from the colUsed bitmask in the case of a generated column, which allows attackers to cause a denial of service * bsc#1157818, CVE-2019-19244: sqlite3,sqlite2,sqlite: The function sqlite3Select in select.c allows a crash if a sub-select uses both DISTINCT and window functions, and also has certain ORDER BY usage * bsc#928701, CVE-2015-3415: sqlite3VdbeExec comparison operator vulnerability * bsc#928700, CVE-2015-3414: sqlite3,sqlite2: dequoting of collation-sequence names * CVE-2020-13434 bsc#1172115: integer overflow in sqlite3_str_vappendf * CVE-2020-13630 bsc#1172234: use-after-free in fts3EvalNextRow * CVE-2020-13631 bsc#1172236: virtual table allowed to be renamed to one of its shadow tables * CVE-2020-13632 bsc#1172240: NULL pointer dereference via crafted matchinfo() query * CVE-2020-13435: Malicious SQL statements could have crashed the process that is running SQLite (bsc#1172091)
Family:unixClass:patch
Status:Reference(s):1000106
1003030
1003032
1004981
1005004
1005005
1007157
1007941
1009100
1009103
1009104
1009105
1009107
1009108
1009109
1009111
1011652
1027282
1041090
1042670
1049825
1073269
1073748
1078326
1078485
1079869
1081750
1082023
1083125
1084650
1085447
1086001
1090368
1090646
1090869
1091427
1094325
1094725
1097356
1100112
1104199
1104202
1104205
1106119
1109209
1109893
1110542
1111319
1112911
1113296
1116574
1116995
1120629
1120630
1120631
1122292
1122293
1122299
1124729
1124734
1127155
1128158
1128378
1130721
1131060
1131823
1134226
1136085
1136976
1137977
1140039
1145521
1149792
1153830
1155094
1157818
1158785
1158787
1158788
1158789
1158790
1158791
1158792
1158793
1158795
1158812
1158958
1158959
1158960
1159035
1159491
1159715
1159723
1159729
1159847
1159850
1160309
1160438
1160439
1162224
1162367
1162825
1164719
1164825
1165894
1170411
1171561
1171928
1172091
1172115
1172234
1172236
1172240
1173641
1175664
1175665
1175671
928700
928701
945401
959329
CVE-2015-3414
CVE-2015-3415
CVE-2016-6153
CVE-2016-7777
CVE-2016-7908
CVE-2016-7909
CVE-2016-8667
CVE-2016-8669
CVE-2016-8910
CVE-2016-9377
CVE-2016-9378
CVE-2016-9379
CVE-2016-9380
CVE-2016-9381
CVE-2016-9382
CVE-2016-9383
CVE-2016-9384
CVE-2016-9385
CVE-2016-9386
CVE-2016-9637
CVE-2017-10989
CVE-2017-13166
CVE-2017-2518
CVE-2017-5715
CVE-2018-1087
CVE-2018-10915
CVE-2018-10925
CVE-2018-11212
CVE-2018-13785
CVE-2018-14526
CVE-2018-1890
CVE-2018-20346
CVE-2018-20532
CVE-2018-20533
CVE-2018-20534
CVE-2018-3136
CVE-2018-3139
CVE-2018-3149
CVE-2018-3169
CVE-2018-3180
CVE-2018-3183
CVE-2018-3214
CVE-2018-5848
CVE-2018-8740
CVE-2018-8781
CVE-2018-8897
CVE-2019-0221
CVE-2019-12418
CVE-2019-1348
CVE-2019-1349
CVE-2019-1350
CVE-2019-1351
CVE-2019-1352
CVE-2019-1353
CVE-2019-1354
CVE-2019-1387
CVE-2019-16168
CVE-2019-17563
CVE-2019-17569
CVE-2019-1787
CVE-2019-1788
CVE-2019-1789
CVE-2019-18348
CVE-2019-19244
CVE-2019-19317
CVE-2019-19603
CVE-2019-19604
CVE-2019-19645
CVE-2019-19646
CVE-2019-19880
CVE-2019-19923
CVE-2019-19924
CVE-2019-19925
CVE-2019-19926
CVE-2019-19959
CVE-2019-20218
CVE-2019-2422
CVE-2019-2449
CVE-2019-3880
CVE-2019-6974
CVE-2019-7221
CVE-2019-8457
CVE-2019-9213
CVE-2019-9674
CVE-2020-13434
CVE-2020-13435
CVE-2020-13630
CVE-2020-13631
CVE-2020-13632
CVE-2020-15358
CVE-2020-15810
CVE-2020-15811
CVE-2020-24606
CVE-2020-8492
CVE-2020-9327
CVE-2020-9484
SUSE-SU-2016:3067-1
SUSE-SU-2018:1536-1
SUSE-SU-2018:2631-1
SUSE-SU-2018:3377-1
SUSE-SU-2018:4064-1
SUSE-SU-2019:0617-1
SUSE-SU-2019:0709-1
SUSE-SU-2019:0897-1
SUSE-SU-2019:1088-1
SUSE-SU-2019:1195-1
SUSE-SU-2019:1601-1
SUSE-SU-2019:2265-1
SUSE-SU-2019:3311-1
SUSE-SU-2020:1498-1
SUSE-SU-2020:1524-1
SUSE-SU-2020:2471-1
Platform(s):openSUSE Leap 15.0
openSUSE Leap 15.1
SUSE Linux Enterprise Server 12 SP1-LTSS
SUSE Linux Enterprise Server 12 SP2
SUSE Linux Enterprise Server 12 SP2-BCL
SUSE Linux Enterprise Server 12 SP2-ESPOS
SUSE Linux Enterprise Server 12 SP2-LTSS
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP3-BCL
SUSE Linux Enterprise Server 12 SP3-ESPOS
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP3-TERADATA
SUSE Linux Enterprise Server 12 SP4
SUSE OpenStack Cloud 7
SUSE OpenStack Cloud 8
SUSE OpenStack Cloud 9
SUSE OpenStack Cloud Crowbar 8
Product(s):
Definition Synopsis
  • openSUSE Leap 15.0 is installed
  • AND Package Information
  • libQt5Concurrent5-5.9.4-lp150.4 is installed
  • OR libQt5Core5-5.9.4-lp150.4 is installed
  • OR libQt5DBus5-5.9.4-lp150.4 is installed
  • OR libQt5Gui5-5.9.4-lp150.4 is installed
  • OR libQt5Network5-5.9.4-lp150.4 is installed
  • OR libQt5OpenGL5-5.9.4-lp150.4 is installed
  • OR libQt5PrintSupport5-5.9.4-lp150.4 is installed
  • OR libQt5Sql5-5.9.4-lp150.4 is installed
  • OR libQt5Sql5-mysql-5.9.4-lp150.4 is installed
  • OR libQt5Sql5-sqlite-5.9.4-lp150.4 is installed
  • OR libQt5Test5-5.9.4-lp150.4 is installed
  • OR libQt5Widgets5-5.9.4-lp150.4 is installed
  • OR libQt5Xml5-5.9.4-lp150.4 is installed
  • OR libqt5-qtbase-platformtheme-gtk3-5.9.4-lp150.4 is installed
  • Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • python-numpy-1.16.1-lp151.5.3 is installed
  • OR python-numpy_1_16_1-gnu-hpc-1.16.1-lp151.5.3 is installed
  • OR python2-numpy-1.16.1-lp151.5.3 is installed
  • OR python2-numpy-devel-1.16.1-lp151.5.3 is installed
  • OR python2-numpy-gnu-hpc-1.16.1-lp151.5.3 is installed
  • OR python2-numpy-gnu-hpc-devel-1.16.1-lp151.5.3 is installed
  • OR python2-numpy_1_16_1-gnu-hpc-1.16.1-lp151.5.3 is installed
  • OR python2-numpy_1_16_1-gnu-hpc-devel-1.16.1-lp151.5.3 is installed
  • OR python3-numpy-1.16.1-lp151.5.3 is installed
  • OR python3-numpy-devel-1.16.1-lp151.5.3 is installed
  • OR python3-numpy-gnu-hpc-1.16.1-lp151.5.3 is installed
  • OR python3-numpy-gnu-hpc-devel-1.16.1-lp151.5.3 is installed
  • OR python3-numpy_1_16_1-gnu-hpc-1.16.1-lp151.5.3 is installed
  • OR python3-numpy_1_16_1-gnu-hpc-devel-1.16.1-lp151.5.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP1-LTSS is installed
  • AND Package Information
  • git-2.12.3-27.22 is installed
  • OR git-core-2.12.3-27.22 is installed
  • OR git-doc-2.12.3-27.22 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2 is installed
  • AND Package Information
  • xen-4.7.1_02-25 is installed
  • OR xen-doc-html-4.7.1_02-25 is installed
  • OR xen-libs-4.7.1_02-25 is installed
  • OR xen-libs-32bit-4.7.1_02-25 is installed
  • OR xen-tools-4.7.1_02-25 is installed
  • OR xen-tools-domU-4.7.1_02-25 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-BCL is installed
  • AND Package Information
  • java-1_8_0-ibm-1.8.0_sr5.25-30.39 is installed
  • OR java-1_8_0-ibm-alsa-1.8.0_sr5.25-30.39 is installed
  • OR java-1_8_0-ibm-devel-1.8.0_sr5.25-30.39 is installed
  • OR java-1_8_0-ibm-plugin-1.8.0_sr5.25-30.39 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-ESPOS is installed
  • AND Package Information
  • kgraft-patch-4_4_121-92_73-default-6-2 is installed
  • OR kgraft-patch-SLE12-SP2_Update_21-6-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-LTSS is installed
  • AND Package Information
  • kgraft-patch-4_4_59-92_24-default-11-2 is installed
  • OR kgraft-patch-SLE12-SP2_Update_9-11-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND Package Information
  • avahi-0.6.32-30 is installed
  • OR avahi-lang-0.6.32-30 is installed
  • OR avahi-utils-0.6.32-30 is installed
  • OR libavahi-client3-0.6.32-30 is installed
  • OR libavahi-client3-32bit-0.6.32-30 is installed
  • OR libavahi-common3-0.6.32-30 is installed
  • OR libavahi-common3-32bit-0.6.32-30 is installed
  • OR libavahi-core7-0.6.32-30 is installed
  • OR libdns_sd-0.6.32-30 is installed
  • OR libdns_sd-32bit-0.6.32-30 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-BCL is installed
  • AND Package Information
  • libssh2-1-1.4.3-20.14 is installed
  • OR libssh2-1-32bit-1.4.3-20.14 is installed
  • OR libssh2_org-1.4.3-20.14 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-ESPOS is installed
  • AND Package Information
  • libsqlite3-0-3.36.0-9.18.1 is installed
  • OR libsqlite3-0-32bit-3.36.0-9.18.1 is installed
  • OR sqlite3-3.36.0-9.18.1 is installed
  • OR sqlite3-devel-3.36.0-9.18.1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND ucode-intel-20191112a-13.56 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND Package Information
  • cups-1.7.5-20.20 is installed
  • OR cups-client-1.7.5-20.20 is installed
  • OR cups-libs-1.7.5-20.20 is installed
  • OR cups-libs-32bit-1.7.5-20.20 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND Package Information
  • libxerces-c-3_1-3.1.1-12 is installed
  • OR libxerces-c-3_1-32bit-3.1.1-12 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 7 is installed
  • AND Package Information
  • libvirt-2.0.0-27.45 is installed
  • OR libvirt-client-2.0.0-27.45 is installed
  • OR libvirt-daemon-2.0.0-27.45 is installed
  • OR libvirt-daemon-config-network-2.0.0-27.45 is installed
  • OR libvirt-daemon-config-nwfilter-2.0.0-27.45 is installed
  • OR libvirt-daemon-driver-interface-2.0.0-27.45 is installed
  • OR libvirt-daemon-driver-libxl-2.0.0-27.45 is installed
  • OR libvirt-daemon-driver-lxc-2.0.0-27.45 is installed
  • OR libvirt-daemon-driver-network-2.0.0-27.45 is installed
  • OR libvirt-daemon-driver-nodedev-2.0.0-27.45 is installed
  • OR libvirt-daemon-driver-nwfilter-2.0.0-27.45 is installed
  • OR libvirt-daemon-driver-qemu-2.0.0-27.45 is installed
  • OR libvirt-daemon-driver-secret-2.0.0-27.45 is installed
  • OR libvirt-daemon-driver-storage-2.0.0-27.45 is installed
  • OR libvirt-daemon-hooks-2.0.0-27.45 is installed
  • OR libvirt-daemon-lxc-2.0.0-27.45 is installed
  • OR libvirt-daemon-qemu-2.0.0-27.45 is installed
  • OR libvirt-daemon-xen-2.0.0-27.45 is installed
  • OR libvirt-doc-2.0.0-27.45 is installed
  • OR libvirt-lock-sanlock-2.0.0-27.45 is installed
  • OR libvirt-nss-2.0.0-27.45 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 8 is installed
  • AND Package Information
  • MozillaFirefox-60.9.0-109.86 is installed
  • OR MozillaFirefox-translations-common-60.9.0-109.86 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 9 is installed
  • AND Package Information
  • mariadb-10.2.29-3.22 is installed
  • OR mariadb-galera-10.2.29-3.22 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 8 is installed
  • AND Package Information
  • MozillaFirefox-68.9.0-109.123 is installed
  • OR MozillaFirefox-translations-common-68.9.0-109.123 is installed
  • BACK