Bug 2152844 (CVE-2022-46908)
| Summary: | CVE-2022-46908 sqlite: safe mode authorizer callback allows disallowed UDFs | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | TEJ RATHI <trathi> |
| Component: | vulnerability | Assignee: | Nobody <nobody> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | aoconnor, bdettelb, caswilli, darunesh, databases-maint, dffrench, dkuc, fjansen, gzaronik, hbraun, jburrell, jkoehler, jwon, kaycoth, micjohns, mmuzila, mschorm, ngough, pkubat, praiskup, psegedy, rgodfrey, rh-spice-bugs, sthirugn, tcarlin, tmeszaro, tsasak, zmiklank |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: |
A flaw was found in the SQLite package. SQLite could allow a local attacker to bypass security restrictions caused by an issue when relying on --safe for the execution of an untrusted CLI script, potentially leading to arbitrary file read/write.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2178899, 2178900, 2178901, 2178902, 2178903, 2156692, 2156693, 2156694, 2156695, 2156696, 2178898, 2178904 | ||
| Bug Blocks: | 2152826 | ||
|
Description
TEJ RATHI
2022-12-13 09:16:11 UTC
Created mingw-sqlite tracking bugs for this issue: Affects: fedora-all [bug 2178901] Created qt5-qtwebengine tracking bugs for this issue: Affects: epel-all [bug 2178899] Affects: fedora-all [bug 2178902] Created sqlite tracking bugs for this issue: Affects: fedora-all [bug 2178898] Created sqlite2 tracking bugs for this issue: Affects: epel-all [bug 2178900] Affects: fedora-all [bug 2178903] Created tdlib tracking bugs for this issue: Affects: fedora-all [bug 2178904] This CVE is present from SQLite 3.37.0 to SQLite 3.40.0[1]. RHEL 8 and 9 contain SQLite 3.26.0 and SQLite 3.34.1, respectively; therefore, RHEL is not affected. [1]: https://nvd.nist.gov/vuln/detail/CVE-2022-46908 |