SB2019041922 - Out-of-bounds read in sqlite (Alpine package)
Published: April 19, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2019-8457)
The vulnerability allows a remote attacker to perform denial of service attack.
The vulnerability exists due to a boundary condition in rtreenode() function when handling invalid rtree tables. A remote attacker can send a specially crafted request to the application, trigger heap out-of-bounds read crash the application.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=8fe3109377cfbec22f6613be0b559e1751bd1db6
- https://git.alpinelinux.org/aports/commit/?id=1833ad9258bf53ebd1f42ccecc5bbf2696c7e19a
- https://git.alpinelinux.org/aports/commit/?id=d5f87185a9e0878348a7b8340fbff4677e23d996
- https://git.alpinelinux.org/aports/commit/?id=5752dce56c5b51a712767fdf310254e6782c50b7
- https://git.alpinelinux.org/aports/commit/?id=77094230c4488f86ee478b67b14436d13e4cd1be
- https://git.alpinelinux.org/aports/commit/?id=7dc62470b3429e2373e0f00cf13129211debf12b
- https://git.alpinelinux.org/aports/commit/?id=b6ffc8832e2cf40ef3bf7ab8428d43c1350fdbf9