CVE-2022-46908
Gentoo Linux Security Advisory 202311-03
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
SQLite through 3.40.0, when relying on --safe for execution of an untrusted CLI script, does not properly implement the azProhibitedFunctions protection mechanism, and instead allows UDF functions such as WRITEFILE.
SQLite hasta 3.40.0, cuando depende de --safe para la ejecución de un script CLI que no es de confianza, no implementa correctamente el mecanismo de protección azProhibitedFunctions y, en su lugar, permite funciones UDF como WRITEFILE.
It was discovered that SQLite incorrectly handled certain protection mechanisms when using a CLI script with the --safe option, contrary to expectations. This issue only affected Ubuntu 22.04 LTS. It was discovered that SQLite incorrectly handled certain memory operations in the sessions extension. A remote attacker could possibly use this issue to cause SQLite to crash, resulting in a denial of service.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-12-12 CVE Reserved
- 2022-12-12 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
https://security.netapp.com/advisory/ntap-20230203-0005 | Third Party Advisory |
|
URL | Date | SRC |
---|---|---|
https://news.ycombinator.com/item?id=33948588 | 2024-08-03 | |
https://sqlite.org/forum/forumpost/07beac8056151b2f | 2024-08-03 |
URL | Date | SRC |
---|---|---|
https://sqlite.org/src/info/cefc032473ac5ad2 | 2023-11-24 |
URL | Date | SRC |
---|---|---|
https://security.gentoo.org/glsa/202311-03 | 2023-11-24 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sqlite Search vendor "Sqlite" | Sqlite Search vendor "Sqlite" for product "Sqlite" | >= 3.37.0 < 3.40.1 Search vendor "Sqlite" for product "Sqlite" and version " >= 3.37.0 < 3.40.1" | - |
Affected
|