SQLite sqlite3VdbeExec Function DoS Vulnerability
SQLite sqlite3VdbeExec Function DoS Vulnerability
Release date:
Updated on:
Affected Systems:
SQLite <3.8.9
Description:
CVE (CAN) ID: CVE-2015-3415
SQLite is an embedded database.
In versions earlier than SQLite 3.8.9, The sqlite3VdbeExec function in vdbe. c does not correctly implement comparison operators. By constructing a CHECK clause, context-independent attackers can exploit this vulnerability to cause DOS.
<* Source: Michal zarewski ([email protected])
*>
Suggestion:
Vendor patch:
SQLite
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.sqlite.org/src/info/c494171f77dc2e5e04cb6d865e688448f04e5920
SQLite3 installation and basic operations
Simple Application of SQLite databases in Ubuntu 12.04
How to install SQLite in Ubuntu 12.04
Basics of SQLite Database
SQLite details: click here
SQLite: click here
This article permanently updates the link address: