cbcvebase.
CVE-2016-6153
published 2016-09-26

CVE-2016-6153: os_unix.c in SQLite before 3.13.0 improperly implements the temporary directory search algorithm, which might allow local users to obtain sensitive…

medium5.9CVSS 3.0
AVLACLPRNUINSUCLILAL
os_unix.c in SQLite before 3.13.0 improperly implements the temporary directory search algorithm, which might allow local users to obtain sensitive information, cause a denial of service (application crash), or have unspecified other impact by leveraging use of the current working directory for temporary files.

Affected

13 ranges
VendorProductVersion rangeFixed in
appleitunes
appleitunes_12.6_for_windows
debiansqlite3< sqlite3 3.13.0-1 (bookworm)sqlite3 3.13.0-1 (bookworm)
fedoraprojectfedora
ghostsqlite3>= 0 < 3.13.0-13.13.0-1
ghostsqlite3>= 0 < 3.13.0-13.13.0-1
ghostsqlite3>= 0 < 3.13.0-13.13.0-1
ghostsqlite3>= 0 < 3.13.0-13.13.0-1
ghostsqlite3>= 0 < 3.11.0-1ubuntu1.23.11.0-1ubuntu1.2
ghostsqlite3>= 0 < 3.22.0-1ubuntu0.13.22.0-1ubuntu0.1
ghostsqlite3>= 0 < 3.8.2-1ubuntu2.2+esm13.8.2-1ubuntu2.2+esm1
opensuseleap
sqlitesqlite<= 3.12.2

CVSS provenance

nvdv3.05.9MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
osv5.9MEDIUM