cbcvebase.
CVE-2016-6153
published 2016-09-26

CVE-2016-6153: os_unix.c in SQLite before 3.13.0 improperly implements the temporary directory search algorithm, which might allow local users to obtain sensitive…

PriorityP420medium5.9CVSS 3.0
AVLACLPRNUINSUCLILAL
EPSS
0.48%
38.3th percentile
os_unix.c in SQLite before 3.13.0 improperly implements the temporary directory search algorithm, which might allow local users to obtain sensitive information, cause a denial of service (application crash), or have unspecified other impact by leveraging use of the current working directory for temporary files.

Affected

13 ranges
VendorProductVersion rangeFixed in
appleitunes
appleitunes_12.6_for_windows
debiansqlite3< sqlite3 3.13.0-1 (bookworm)sqlite3 3.13.0-1 (bookworm)
fedoraprojectfedora
ghostsqlite3>= 0 < 3.13.0-13.13.0-1
ghostsqlite3>= 0 < 3.13.0-13.13.0-1
ghostsqlite3>= 0 < 3.13.0-13.13.0-1
ghostsqlite3>= 0 < 3.13.0-13.13.0-1
ghostsqlite3>= 0 < 3.11.0-1ubuntu1.23.11.0-1ubuntu1.2
ghostsqlite3>= 0 < 3.22.0-1ubuntu0.13.22.0-1ubuntu0.1
ghostsqlite3>= 0 < 3.8.2-1ubuntu2.2+esm13.8.2-1ubuntu2.2+esm1
opensuseleap
sqlitesqlite<= 3.12.2

CVSS provenance

nvdv3.05.9MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.