SCIENTIFIC-LINUX-ERRATA Archives

August 2015

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Pat Riehecky <[log in to unmask]>
Reply To:
Date:
Mon, 17 Aug 2015 16:37:16 +0000
Content-Type:
text/plain
Parts/Attachments:
text/plain (34 lines)
Synopsis:          Moderate: sqlite security update
Advisory ID:       SLSA-2015:1634-1
Issue Date:        2015-08-17
CVE Numbers:       CVE-2015-3416
--

It was found that SQLite's sqlite3VXPrintf() function did not properly
handle precision and width values during floating-point conversions. A
local attacker could submit a specially crafted SELECT statement that
would crash the SQLite process, or have other unspecified impacts.
(CVE-2015-3416)
--

SL6
  x86_64
    sqlite-3.6.20-1.el6_7.2.i686.rpm
    sqlite-3.6.20-1.el6_7.2.x86_64.rpm
    sqlite-debuginfo-3.6.20-1.el6_7.2.i686.rpm
    sqlite-debuginfo-3.6.20-1.el6_7.2.x86_64.rpm
    lemon-3.6.20-1.el6_7.2.x86_64.rpm
    sqlite-devel-3.6.20-1.el6_7.2.i686.rpm
    sqlite-devel-3.6.20-1.el6_7.2.x86_64.rpm
    sqlite-doc-3.6.20-1.el6_7.2.x86_64.rpm
    sqlite-tcl-3.6.20-1.el6_7.2.x86_64.rpm
  i386
    sqlite-3.6.20-1.el6_7.2.i686.rpm
    sqlite-debuginfo-3.6.20-1.el6_7.2.i686.rpm
    lemon-3.6.20-1.el6_7.2.i686.rpm
    sqlite-devel-3.6.20-1.el6_7.2.i686.rpm
    sqlite-doc-3.6.20-1.el6_7.2.i686.rpm
    sqlite-tcl-3.6.20-1.el6_7.2.i686.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2