Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 725118 - dev-db/sqlite: Multiple vulnerabilities (CVE-2020-{13434,13435})
Summary: dev-db/sqlite: Multiple vulnerabilities (CVE-2020-{13434,13435})
Status: RESOLVED DUPLICATE of bug 716748
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2020-05-24 22:55 UTC by Sam James
Modified: 2020-06-03 05:05 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-05-24 22:55:53 UTC
* CVE-2020-13434

Description:
"SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c."

Patch: https://www.sqlite.org/src/info/23439ea582241138
Patch: https://www.sqlite.org/src/info/d08d3405878d394e 

* CVE-2020-13435

Description:
"SQLite through 3.32.0 has a segmentation fault in sqlite3ExprCodeTarget in expr.c."

Patch: https://www.sqlite.org/src/info/7a5279a25c57adf1
Comment 1 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-05-24 22:56:50 UTC
@maintainer(s), you may want to apply these patches before we go through the stable routine for bug 716748. Please let us know what you plan to do?
Comment 2 Arfrever Frehtes Taifersar Arahesis 2020-06-03 04:57:37 UTC
(In reply to Sam James (sec padawan) from comment #0)
> * CVE-2020-13434
> 
> Description:
> "SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in
> printf.c."
> 
> Report: https://sqlite.org/src/info/23439ea582241138
> Commit: https://sqlite.org/src/info/d08d3405878d394e

This commit is included in SQLite 3.32.1.

> * CVE-2020-13435
> 
> Description:
> "SQLite through 3.32.0 has a segmentation fault in sqlite3ExprCodeTarget in
> expr.c."
> 
> Report: https://sqlite.org/src/info/7a5279a25c57adf1
> Commit: https://sqlite.org/src/info/572105de1d44bca4

This commit is included in SQLite 3.32.1.
Comment 3 Arfrever Frehtes Taifersar Arahesis 2020-06-03 05:05:09 UTC

*** This bug has been marked as a duplicate of bug 716748 ***