CVE-2016-6153Improper Input Validation in Sqlite

Severity
5.9MEDIUMNVD
EPSS
0.0%
top 90.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 26
Latest updateMay 14

Description

os_unix.c in SQLite before 3.13.0 improperly implements the temporary directory search algorithm, which might allow local users to obtain sensitive information, cause a denial of service (application crash), or have unspecified other impact by leveraging use of the current working directory for temporary files.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LExploitability: 2.5 | Impact: 3.4

Affected Packages3 packages

Debianghost/sqlite3< 3.13.0-1+3
NVDsqlite/sqlite3.12.2
NVDopensuse/leap42.1

Also affects: Fedora 24

Patches

🔴Vulnerability Details

3
GHSA
GHSA-c7vx-xpvf-fj57: os_unix2022-05-14
OSV
CVE-2016-6153: os_unix2016-09-26
CVEList
CVE-2016-6153: os_unix2016-09-26

📋Vendor Advisories

6
Ubuntu
SQLite vulnerabilities2019-06-19
Ubuntu
SQLite vulnerabilities2019-06-19
Apple
CVE-2016-6153: iTunes 12.6 for Windows2017-03-21
Apple
CVE-2016-6153: iTunes 12.62017-03-21
Red Hat
sqlite: Tempdir selection vulnerability2016-07-01

💬Community

6
Bugzilla
CVE-2016-6153 sqlite2: sqlite: Tempdir selection vulnerability [epel-all]2016-07-04
Bugzilla
CVE-2016-6153 mingw-sqlite: sqlite: Tempdir selection vulnerability [epel-7]2016-07-04
Bugzilla
CVE-2016-6153 mingw-sqlite: sqlite: Tempdir selection vulnerability [fedora-all]2016-07-04
Bugzilla
CVE-2016-6153 sqlite2: sqlite: Tempdir selection vulnerability [fedora-all]2016-07-04
Bugzilla
CVE-2016-6153 sqlite: Tempdir selection vulnerability [fedora-all]2016-07-04
CVE-2016-6153 — Improper Input Validation in Sqlite | cvebase