SB2019020723 - Fedora 29 update for mingw-sqlite
Published: February 7, 2019 Updated: April 24, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 secuirty vulnerabilities.
1) Resource management error (CVE-ID: CVE-2016-6153)
The vulnerability allows a local user to perform a denial of service (DoS) attack or gain access to sensitive information.
The vulnerability exists due to the application improperly implements the temporary directory search algorithm. A local user can make the application use the current working directory for storing temporary files and gain access to sensitive information or perform denial of service attack.
2) NULL pointer dereference (CVE-ID: CVE-2018-8740)
The vulnerability allows a remote authenticated attacker to cause DoS condition on the target system.The weakness exists in the build.c and prepare.c source codes files due to NULL pointer dereference. A remote attacker can cause the service to crash.
3) SQL injection (CVE-ID: CVE-2018-20346)
The vulnerability allows a remote attacker to execute arbitrary SQL queries in database.
The vulnerability exists due to insufficient sanitization of user-supplied data in the SQLite component. A remote attacker can send a specially specially crafted request to the affected application and execute arbitrary SQL commands within the application database.
Successful exploitation of this vulnerability may allow a remote attacker to read, delete, modify data in database and gain complete control over the affected application.
Remediation
Install update from vendor's website.