Vulnerability Description
A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionReadRecord of the file ext/session/sqlite3session.c of the component make alltest Handler. The manipulation leads to heap-based buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-248999.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sqlite | Sqlite | <= 3.43.0 |
| Fedoraproject | Fedora | 38 |
Related Weaknesses (CWE)
References
- https://lists.fedoraproject.org/archives/list/[email protected]Issue TrackingThird Party Advisory
- https://lists.fedoraproject.org/archives/list/[email protected]Issue TrackingThird Party Advisory
- https://security.netapp.com/advisory/ntap-20240112-0008/
- https://sqlite.org/forum/forumpost/5bcbf4571cExploit
- https://sqlite.org/src/info/0e4e7a05c4204b47Patch
- https://vuldb.com/?ctiid.248999Permissions Required
- https://vuldb.com/?id.248999Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2024/09/msg00050.html
- https://lists.fedoraproject.org/archives/list/[email protected]Issue TrackingThird Party Advisory
- https://lists.fedoraproject.org/archives/list/[email protected]Issue TrackingThird Party Advisory
- https://security.netapp.com/advisory/ntap-20240112-0008/
- https://sqlite.org/forum/forumpost/5bcbf4571cExploit
- https://sqlite.org/src/info/0e4e7a05c4204b47Patch
- https://vuldb.com/?ctiid.248999Permissions Required
- https://vuldb.com/?id.248999Third Party Advisory
FAQ
What is CVE-2023-7104?
CVE-2023-7104 is a vulnerability with a CVSS score of 5.5 (MEDIUM). A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionReadRecord of the file ext/session/sqlite3session.c of the component make al...
How severe is CVE-2023-7104?
CVE-2023-7104 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-7104?
Check the references section above for vendor advisories and patch information. Affected products include: Sqlite Sqlite, Fedoraproject Fedora.