CVE-2018-20346
published 2018-12-21CVE-2018-20346: SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries that occur after…
PriorityP355high8.1CVSS 3.0
AVNACHPRNUINSUCHIHAH
EPSS
9.86%
95.0th percentile
SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries that occur after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases), aka Magellan.
Affected
41 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tika | — | — |
| apple | icloud | <= 7.10 | — |
| apple | icloud_for_windows | — | — |
| apple | ios | — | — |
| apple | iphone_os | < 12.1.3 | 12.1.3 |
| apple | itunes | <= 12.9.3 | — |
| apple | itunes_12.9.3_for_windows | — | — |
| apple | mac_os_x | < 10.14.3 | 10.14.3 |
| apple | macos_mojave_10.14.3_security_update_2019-001_high_sierra_security_update_2019-0 | — | — |
| apple | tvos | < 12.1.2 | 12.1.2 |
| apple | tvos | — | — |
| apple | watchos | < 5.1.3 | 5.1.3 |
| apple | watchos | — | — |
| chromium | chromium | >= 0 < 71.0.3578.80-1 | 71.0.3578.80-1 |
| chromium | chromium | >= 0 < 71.0.3578.80-1 | 71.0.3578.80-1 |
| chromium | chromium | >= 0 < 71.0.3578.80-1 | 71.0.3578.80-1 |
| chromium | chromium | >= 0 < 71.0.3578.80-1 | 71.0.3578.80-1 |
| debian | chromium | < chromium 71.0.3578.80-1 (bookworm) | chromium 71.0.3578.80-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | sqlite3 | < sqlite3 3.25.3-1 (bookworm) | sqlite3 3.25.3-1 (bookworm) |
| debian | sqlite3 | < chromium 71.0.3578.80-1 (bookworm) | chromium 71.0.3578.80-1 (bookworm) |
| ghost | sqlite3 | >= 0 < 3.25.3-1 | 3.25.3-1 |
| ghost | sqlite3 | >= 0 < 3.25.3-1 | 3.25.3-1 |
| ghost | sqlite3 | >= 0 < 3.25.3-1 | 3.25.3-1 |
| ghost | sqlite3 | >= 0 < 3.25.3-1 | 3.25.3-1 |
CVSS provenance
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.1HIGH
vendor_apache8.1HIGH
vendor_debian8.1HIGH
vendor_msrc8.1HIGH
vendor_redhat8.1HIGH
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
SQLite vulnerabilities
vendor_ubuntu·2019-06-19·CVSS 5.9
CVE-2016-6153 [MEDIUM] SQLite vulnerabilities
Title: SQLite vulnerabilities
Summary: Several security issues were fixed in SQLite.
USN-4019-1 fixed several vulnerabilities in sqlite3. This update provides
the corresponding update for Ubuntu 12.04 ESM and 14.04 ESM.
Original advisory details:
It was discovered that SQLite incorrectly handled certain SQL files.
An attacker could possibly use this issue to execute arbitrary code
or cause a denial of service. (CVE-2017-2518)
It was discovered that SQLite incorrectly handled certain queries.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2018-20346, CVE-2018-20506)
It was discovered that SQLite incorrectly handled certain inputs.
An attacker could possibly use this issue to access sensitive information.
(CVE-2019-8457)
It was discovered that SQLite incorre
Ubuntu
SQLite vulnerabilities
vendor_ubuntu·2019-06-19·CVSS 5.9
CVE-2016-6153 [MEDIUM] SQLite vulnerabilities
Title: SQLite vulnerabilities
Summary: Several security issues were fixed in SQLite.
It was discovered that SQLite incorrectly handled certain SQL files.
An attacker could possibly use this issue to execute arbitrary code
or cause a denial of service. This issue only affected Ubuntu 16.04
LTS. (CVE-2017-2518, CVE-2017-2520)
It was discovered that SQLite incorrectly handled certain queries.
An attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 18.04 LTS and Ubuntu 18.10. (CVE-2018-20505)
It was discovered that SQLite incorrectly handled certain queries.
An attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and
Ubuntu 18.10. (CVE-2018-20346, CVE-2018-20506)
It was di
Microsoft
SQLite before 3.25.3 when the FTS3 extension is enabled encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3
vendor_msrc·2019-04-09·CVSS 8.1
CVE-2018-20506 [HIGH] CWE-190 SQLite before 3.25.3 when the FTS3 extension is enabled encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3
SQLite before 3.25.3 when the FTS3 extension is enabled encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases). This is a different vulnerability than CVE-2018-20346.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed.
Android
CVE-2018-20346: Android Security Bulletin 2019-03-01
CVE: CVE-2018-20346
Severity: HIGH
Type: EoP
Affected AOSP versions: 7
vendor_android·2019-03-01·CVSS 8.1
CVE-2018-20346 [HIGH] CVE-2018-20346: Android Security Bulletin 2019-03-01
CVE: CVE-2018-20346
Severity: HIGH
Type: EoP
Affected AOSP versions: 7
Android Security Bulletin 2019-03-01
CVE: CVE-2018-20346
Severity: HIGH
Type: EoP
Affected AOSP versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1, 9
References: A-121156452
Apple
CVE-2018-20346: iTunes 12.9.3 for Windows
vendor_apple·2019-01-24·CVSS 8.1
CVE-2018-20346 [HIGH] CVE-2018-20346: iTunes 12.9.3 for Windows
Apple Security Update: About the security content of iTunes 12.9.3 for Windows
Product: iTunes 12.9.3 for Windows
CVE: CVE-2018-20346
Component: SQLite
Impact: A maliciously crafted SQL query may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved input validation.
Apple
CVE-2018-20346: tvOS 12.1.2
vendor_apple·2019-01-22·CVSS 8.1
CVE-2018-20346 [HIGH] CVE-2018-20346: tvOS 12.1.2
Apple Security Update: About the security content of tvOS 12.1.2
Product: tvOS
Version: 12.1.2
CVE: CVE-2018-20346
Component: SQLite
Impact: A maliciously crafted SQL query may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved input validation.
Apple
CVE-2018-20346: watchOS 5.1.3
vendor_apple·2019-01-22·CVSS 8.1
CVE-2018-20346 [HIGH] CVE-2018-20346: watchOS 5.1.3
Apple Security Update: About the security content of watchOS 5.1.3
Product: watchOS
Version: 5.1.3
CVE: CVE-2018-20346
Component: SQLite
Impact: A maliciously crafted SQL query may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved input validation.
Apple
CVE-2018-20346: iCloud for Windows 7.10
vendor_apple·2019-01-22·CVSS 8.1
CVE-2018-20346 [HIGH] CVE-2018-20346: iCloud for Windows 7.10
Apple Security Update: About the security content of iCloud for Windows 7.10
Product: iCloud for Windows
Version: 7.10
CVE: CVE-2018-20346
Component: SQLite
Impact: A maliciously crafted SQL query may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved input validation.
Apple
CVE-2018-20346: iOS 12.1.3
vendor_apple·2019-01-22·CVSS 8.1
CVE-2018-20346 [HIGH] CVE-2018-20346: iOS 12.1.3
Apple Security Update: About the security content of iOS 12.1.3
Product: iOS
Version: 12.1.3
CVE: CVE-2018-20346
Component: SQLite
Impact: A maliciously crafted SQL query may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved input validation.
Apple
CVE-2018-20346: macOS Mojave 10.14.3, Security Update 2019-001 High Sierra, Security Update 2019-001 Sierra
vendor_apple·2019-01-22·CVSS 8.1
CVE-2018-20346 [HIGH] CVE-2018-20346: macOS Mojave 10.14.3, Security Update 2019-001 High Sierra, Security Update 2019-001 Sierra
Apple Security Update: About the security content of macOS Mojave 10.14.3, Security Update 2019-001 High Sierra, Security Update 2019-001 Sierra
Product: macOS Mojave 10.14.3, Security Update 2019-001 High Sierra, Security Update 2019-001 Sierra
CVE: CVE-2018-20346
Component: SQLite
Impact: A maliciously crafted SQL query may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved input validation.
Microsoft
SQLite before 3.25.3 when the FTS3 extension is enabled encounters an integer overflow (and resultant buffer overflow) for FTS3 queries that occur after crafted changes to FTS3 shadow tables allowing
vendor_msrc·2018-12-11·CVSS 8.1
CVE-2018-20346 [HIGH] CWE-190 SQLite before 3.25.3 when the FTS3 extension is enabled encounters an integer overflow (and resultant buffer overflow) for FTS3 queries that occur after crafted changes to FTS3 shadow tables allowing
SQLite before 3.25.3 when the FTS3 extension is enabled encounters an integer overflow (and resultant buffer overflow) for FTS3 queries that occur after crafted changes to FTS3 shadow tables allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases) aka Magellan.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why w
Red Hat
sqlite: Multiple flaws in sqlite which can be triggered via corrupted internal databases (Magellan)
vendor_redhat·2018-12-04·CVSS 8.1
CVE-2018-20346 [HIGH] sqlite: Multiple flaws in sqlite which can be triggered via corrupted internal databases (Magellan)
sqlite: Multiple flaws in sqlite which can be triggered via corrupted internal databases (Magellan)
SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries that occur after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases), aka Magellan.
Multiple flaws were found in sqlite. An attacker having the ability to run arbitrary SQL commands could use this flaw to execute arbitrary code with the permission of the user running the sqlite application.
Statement: This flaw does not affect the versions of sqlite package shipped with Red Hat Enterprise Linux 5, 6 and 7. This flaw in s
Red Hat
sqlite: Multiple flaws in sqlite which can be triggered via corrupted internal databases (Magellan)
vendor_redhat·2018-12-04·CVSS 8.1
CVE-2018-20506 [HIGH] sqlite: Multiple flaws in sqlite which can be triggered via corrupted internal databases (Magellan)
sqlite: Multiple flaws in sqlite which can be triggered via corrupted internal databases (Magellan)
SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases). This is a different vulnerability than CVE-2018-20346.
Multiple flaws were found in sqlite. An attacker having the ability to run arbitrary SQL commands could use this flaw to execute arbitrary code with the permission of the user running the sqlite application.
Statement: This flaw does not affect the versions of sqlite package
Debian
CVE-2018-20506: sqlite3 - SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer ...
vendor_debian·2018·CVSS 8.1
CVE-2018-20506 [HIGH] CVE-2018-20506: sqlite3 - SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer ...
SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases). This is a different vulnerability than CVE-2018-20346.
Scope: local
bookworm: resolved (fixed in 3.25.3-1)
bullseye: resolved (fixed in 3.25.3-1)
forky: resolved (fixed in 3.25.3-1)
sid: resolved (fixed in 3.25.3-1)
trixie: resolved (fixed in 3.25.3-1)
Debian
CVE-2018-20346: chromium - SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer ...
vendor_debian·2018·CVSS 8.1
CVE-2018-20346 [HIGH] CVE-2018-20346: chromium - SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer ...
SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries that occur after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases), aka Magellan.
Scope: local
bookworm: resolved (fixed in 71.0.3578.80-1)
bullseye: resolved (fixed in 71.0.3578.80-1)
forky: resolved (fixed in 71.0.3578.80-1)
sid: resolved (fixed in 71.0.3578.80-1)
trixie: resolved (fixed in 71.0.3578.80-1)
Apache
Apache tika: CVE-2018-20346
vendor_apache·CVSS 8.1
CVE-2018-20346 [HIGH] Apache tika: CVE-2018-20346
Apache tika: CVE-2018-20346
(Provided) SQLite before 3.52.3 allows remote attackers to execute arbitrary code Pat Cashman (notified Tika team) ?-1.20
GHSA
GHSA-wpf6-c3rx-7xrj: SQLite before 3
ghsa_unreviewed·2022-05-13
CVE-2018-20346 [HIGH] CWE-190 GHSA-wpf6-c3rx-7xrj: SQLite before 3
SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries that occur after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases), aka Magellan.
GHSA
GHSA-hfxx-8v8g-6rcx: SQLite before 3
ghsa_unreviewed·2022-05-13·CVSS 8.1
CVE-2018-20506 [HIGH] CWE-190 GHSA-hfxx-8v8g-6rcx: SQLite before 3
SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases). This is a different vulnerability than CVE-2018-20346.
OSV
sqlite3 vulnerabilities
osv·2019-06-19·CVSS 5.9
CVE-2017-2518 [MEDIUM] sqlite3 vulnerabilities
sqlite3 vulnerabilities
It was discovered that SQLite incorrectly handled certain SQL files.
An attacker could possibly use this issue to execute arbitrary code
or cause a denial of service. This issue only affected Ubuntu 16.04
LTS. (CVE-2017-2518, CVE-2017-2520)
It was discovered that SQLite incorrectly handled certain queries.
An attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 18.04 LTS and Ubuntu 18.10. (CVE-2018-20505)
It was discovered that SQLite incorrectly handled certain queries.
An attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and
Ubuntu 18.10. (CVE-2018-20346, CVE-2018-20506)
It was discovered that SQLite incorrectly handled certain inputs.
An at
OSV
sqlite3 vulnerabilities
osv·2019-06-19·CVSS 5.9
CVE-2017-2518 [MEDIUM] sqlite3 vulnerabilities
sqlite3 vulnerabilities
USN-4019-1 fixed several vulnerabilities in sqlite3. This update provides
the corresponding update for Ubuntu 12.04 ESM and 14.04 ESM.
Original advisory details:
It was discovered that SQLite incorrectly handled certain SQL files.
An attacker could possibly use this issue to execute arbitrary code
or cause a denial of service. (CVE-2017-2518)
It was discovered that SQLite incorrectly handled certain queries.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2018-20346, CVE-2018-20506)
It was discovered that SQLite incorrectly handled certain inputs.
An attacker could possibly use this issue to access sensitive information.
(CVE-2019-8457)
It was discovered that SQLite incorrectly handled certain inputs.
An attacker could possibly use th
OSV
CVE-2018-20506: SQLite before 3
osv·2019-04-03·CVSS 8.1
CVE-2018-20506 [HIGH] CVE-2018-20506: SQLite before 3
SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases). This is a different vulnerability than CVE-2018-20346.
OSV
CVE-2018-20346: SQLite before 3
osv·2018-12-21·CVSS 8.1
CVE-2018-20346 [HIGH] CVE-2018-20346: SQLite before 3
SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries that occur after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases), aka Magellan.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-20346 mingw-sqlite: sqlite: Multiple flaws in sqlite which can be triggered via corrupted internal databases (Magellan) [epel-7]
bugzilla·2018-12-17·CVSS 8.1
CVE-2018-20346 [HIGH] CVE-2018-20346 mingw-sqlite: sqlite: Multiple flaws in sqlite which can be triggered via corrupted internal databases (Magellan) [epel-7]
CVE-2018-20346 mingw-sqlite: sqlite: Multiple flaws in sqlite which can be triggered via corrupted internal databases (Magellan) [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit messag
Bugzilla
CVE-2018-20346 mingw-sqlite: sqlite: Multiple flaws in sqlite which can be triggered via corrupted internal databases (Magellan) [fedora-all]
bugzilla·2018-12-17·CVSS 8.1
CVE-2018-20346 [HIGH] CVE-2018-20346 mingw-sqlite: sqlite: Multiple flaws in sqlite which can be triggered via corrupted internal databases (Magellan) [fedora-all]
CVE-2018-20346 mingw-sqlite: sqlite: Multiple flaws in sqlite which can be triggered via corrupted internal databases (Magellan) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commi
Bugzilla
CVE-2018-20346 sqlite: Multiple flaws in sqlite which can be triggered via corrupted internal databases (Magellan) [fedora-all]
bugzilla·2018-12-15·CVSS 8.1
CVE-2018-20346 [HIGH] CVE-2018-20346 sqlite: Multiple flaws in sqlite which can be triggered via corrupted internal databases (Magellan) [fedora-all]
CVE-2018-20346 sqlite: Multiple flaws in sqlite which can be triggered via corrupted internal databases (Magellan) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NO
Bugzilla
CVE-2018-20346 CVE-2018-20505 CVE-2018-20506 sqlite: Multiple flaws in sqlite which can be triggered via corrupted internal databases (Magellan)
bugzilla·2018-12-14·CVSS 8.1
CVE-2018-20346 [HIGH] CVE-2018-20346 CVE-2018-20505 CVE-2018-20506 sqlite: Multiple flaws in sqlite which can be triggered via corrupted internal databases (Magellan)
CVE-2018-20346 CVE-2018-20505 CVE-2018-20506 sqlite: Multiple flaws in sqlite which can be triggered via corrupted internal databases (Magellan)
Multiple flaws were found in sqlite. An attacker who is able to run arbitrary SQL statements could use this flaw to corrupt the internal databases, which can lead to arbitrary code execution as the user running sqlite.
This issue was fixed via sqlite-3.25.3 release at:
https://www.sqlite.org/releaselog/3_25_3.html
Also sqlite-3.36 introduced SQLITE_DBCONFIG_DEFENSIVE option which when added to the config file, could prevent attackers for corrupting the internal database files. This could however break applications which require users to write these database files.
https://www.sqlite.org/releaselog/3_26_0.html
https://www.sqlite.org/c3ref/c_dbco
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00040.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00070.htmlhttp://www.securityfocus.com/bid/106323https://access.redhat.com/articles/3758321https://blade.tencent.com/magellan/index_en.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1659379https://bugzilla.redhat.com/show_bug.cgi?id=1659677https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.htmlhttps://chromium.googlesource.com/chromium/src/+/c368e30ae55600a1c3c9cb1710a54f9c55de786ehttps://crbug.com/900910https://github.com/zhuowei/worthdoingbadly.com/blob/master/_posts/2018-12-14-sqlitebug.htmlhttps://kc.mcafee.com/corporate/index?page=content&id=SB10365https://lists.debian.org/debian-lts-announce/2018/12/msg00012.htmlhttps://lists.debian.org/debian-lts-announce/2020/08/msg00037.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PU4NZ6DDU4BEM3ACM3FM6GLEPX56ZQXK/https://news.ycombinator.com/item?id=18685296https://security.gentoo.org/glsa/201904-21https://sqlite.org/src/info/940f2adc8541a838https://sqlite.org/src/info/d44318f59044162ehttps://support.apple.com/HT209443https://support.apple.com/HT209446https://support.apple.com/HT209447https://support.apple.com/HT209448https://support.apple.com/HT209450https://support.apple.com/HT209451https://usn.ubuntu.com/4019-1/https://usn.ubuntu.com/4019-2/https://worthdoingbadly.com/sqlitebug/https://www.freebsd.org/security/advisories/FreeBSD-EN-19:03.sqlite.aschttps://www.mail-archive.com/sqlite-users%40mailinglists.sqlite.org/msg113218.htmlhttps://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.sqlite.org/releaselog/3_25_3.htmlhttps://www.synology.com/security/advisory/Synology_SA_18_61http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00040.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00070.htmlhttp://www.securityfocus.com/bid/106323https://access.redhat.com/articles/3758321https://blade.tencent.com/magellan/index_en.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1659379https://bugzilla.redhat.com/show_bug.cgi?id=1659677https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.htmlhttps://chromium.googlesource.com/chromium/src/+/c368e30ae55600a1c3c9cb1710a54f9c55de786ehttps://crbug.com/900910https://github.com/zhuowei/worthdoingbadly.com/blob/master/_posts/2018-12-14-sqlitebug.htmlhttps://kc.mcafee.com/corporate/index?page=content&id=SB10365https://lists.debian.org/debian-lts-announce/2018/12/msg00012.htmlhttps://lists.debian.org/debian-lts-announce/2020/08/msg00037.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PU4NZ6DDU4BEM3ACM3FM6GLEPX56ZQXK/https://news.ycombinator.com/item?id=18685296https://security.gentoo.org/glsa/201904-21https://sqlite.org/src/info/940f2adc8541a838https://sqlite.org/src/info/d44318f59044162ehttps://support.apple.com/HT209443https://support.apple.com/HT209446https://support.apple.com/HT209447https://support.apple.com/HT209448https://support.apple.com/HT209450https://support.apple.com/HT209451https://usn.ubuntu.com/4019-1/https://usn.ubuntu.com/4019-2/https://worthdoingbadly.com/sqlitebug/https://www.freebsd.org/security/advisories/FreeBSD-EN-19:03.sqlite.aschttps://www.mail-archive.com/sqlite-users%40mailinglists.sqlite.org/msg113218.htmlhttps://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.sqlite.org/releaselog/3_25_3.htmlhttps://www.synology.com/security/advisory/Synology_SA_18_61
2018-12-21
Published