Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 810031 (CVE-2021-36690)

Summary: dev-db/sqlite: null pointer dereference (CVE-2021-36690)
Product: Gentoo Security Reporter: John Helmert III <ajak>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: CONFIRMED ---    
Severity: minor CC: arfrever.fta, floppym
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://www.sqlite.org/forum/forumpost/718c0a8d17
Whiteboard: B3 [upstream/ebuild]
Package list:
Runtime testing required: ---

Description John Helmert III gentoo-dev Security 2021-08-24 16:36:53 UTC
CVE-2021-36690:

Segmentation fault vulnerability in SQLite sqlite3 3.36.0 via the idxGetTableInfo function, in which a crafted SQL query can cause a denial of service


Seems there's a patch: https://sqlite.org/src/info/b1e0c22ec981cf5f