SB2020050731 - Input validation error in sqlite (Alpine package)
Published: May 7, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2020-11655)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input when the AggInfo object's initialization is mishandled. A remote attacker can pass specially crafted input via a malformed window-function query to the application and perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=7b239bab22495734019a47cf43e9910e049e98a7
- https://git.alpinelinux.org/aports/commit/?id=79233d80a2da2627e57d65211329b6042279e306
- https://git.alpinelinux.org/aports/commit/?id=a31444c0192891f76398568d2752e94a7a371f2e
- https://git.alpinelinux.org/aports/commit/?id=a946d0746f23d2eb717f3c7d7f83c170f6454a90
- https://git.alpinelinux.org/aports/commit/?id=bc642570e0a6187ba125ae75709a929f82d6774f
- https://git.alpinelinux.org/aports/commit/?id=f50538f44cd11bfe950572e096b1bebdb2348a46