CVE-2023-7104

Description

A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionReadRecord of the file ext/session/sqlite3session.c of the component make alltest Handler. The manipulation leads to heap-based buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-248999.

Risk Information

Base Score
7.3
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS Score
Exploitation Probability
0.129

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in IBM WebMethods Integration Server 10.15Windows
Multiple Vulnerabilities are affected in IBM WebMethods Integration Server 10.11Windows
Multiple Vulnerabilities are affected in IBM WebMethods Integration Server 11.1Windows
(RHSA-2024:0253)Moderate: security update lemon-3.26.0-19.el8_9.x86_64.rpmLinux
(RHSA-2024:0253)Moderate: security update lemon-debuginfo-3.26.0-19.el8_9.i686.rpmLinux
(RHSA-2024:0253)Moderate: security update lemon-debuginfo-3.26.0-19.el8_9.x86_64.rpmLinux
(RHSA-2024:0253)Moderate: security update sqlite-3.26.0-19.el8_9.i686.rpmLinux
(RHSA-2024:0253)Moderate: security update sqlite-3.26.0-19.el8_9.x86_64.rpmLinux
(RHSA-2024:0253)Moderate: security update sqlite-analyzer-debuginfo-3.26.0-19.el8_9.i686.rpmLinux
(RHSA-2024:0253)Moderate: security update sqlite-analyzer-debuginfo-3.26.0-19.el8_9.x86_64.rpmLinux
(RHSA-2024:0253)Moderate: security update sqlite-debuginfo-3.26.0-19.el8_9.i686.rpmLinux
(RHSA-2024:0253)Moderate: security update sqlite-debuginfo-3.26.0-19.el8_9.x86_64.rpmLinux
(RHSA-2024:0253)Moderate: security update sqlite-debugsource-3.26.0-19.el8_9.i686.rpmLinux
(RHSA-2024:0253)Moderate: security update sqlite-debugsource-3.26.0-19.el8_9.x86_64.rpmLinux
(RHSA-2024:0253)Moderate: security update sqlite-devel-3.26.0-19.el8_9.i686.rpmLinux
(RHSA-2024:0253)Moderate: security update sqlite-devel-3.26.0-19.el8_9.x86_64.rpmLinux
(RHSA-2024:0253)Moderate: security update sqlite-doc-3.26.0-19.el8_9.noarch.rpmLinux
(RHSA-2024:0253)Moderate: security update sqlite-libs-3.26.0-19.el8_9.i686.rpmLinux
(RHSA-2024:0253)Moderate: security update sqlite-libs-3.26.0-19.el8_9.x86_64.rpmLinux
(RHSA-2024:0253)Moderate: security update sqlite-libs-debuginfo-3.26.0-19.el8_9.i686.rpmLinux
(RHSA-2024:0253)Moderate: security update sqlite-libs-debuginfo-3.26.0-19.el8_9.x86_64.rpmLinux
(RHSA-2024:0253)Moderate: security update sqlite-tcl-debuginfo-3.26.0-19.el8_9.i686.rpmLinux
(RHSA-2024:0253)Moderate: security update sqlite-tcl-debuginfo-3.26.0-19.el8_9.x86_64.rpmLinux
Lemon update (ELSA-2024-0253) lemon-3.26.0-19.0.1.el8_9.x86_64.rpmLinux
Sqlite update (ELSA-2024-0253) sqlite-3.26.0-19.0.1.el8_9.i686.rpmLinux
Sqlite update (ELSA-2024-0253) sqlite-3.26.0-19.0.1.el8_9.x86_64.rpmLinux
Sqlite-devel update (ELSA-2024-0253) sqlite-devel-3.26.0-19.0.1.el8_9.i686.rpmLinux
Sqlite-devel update (ELSA-2024-0253) sqlite-devel-3.26.0-19.0.1.el8_9.x86_64.rpmLinux
Sqlite-doc update (ELSA-2024-0253) sqlite-doc-3.26.0-19.0.1.el8_9.noarch.rpmLinux
Sqlite-libs update (ELSA-2024-0253) sqlite-libs-3.26.0-19.0.1.el8_9.i686.rpmLinux
Sqlite-libs update (ELSA-2024-0253) sqlite-libs-3.26.0-19.0.1.el8_9.x86_64.rpmLinux
sqlite security update (RLSA-2024:0253) lemon-3.26.0-19.el8_9.x86_64.rpmLinux
sqlite security update (RLSA-2024:0253) sqlite-3.26.0-19.el8_9.i686.rpmLinux
sqlite security update (RLSA-2024:0253) sqlite-3.26.0-19.el8_9.x86_64.rpmLinux
sqlite security update (RLSA-2024:0253) sqlite-doc-3.26.0-19.el8_9.noarch.rpmLinux
sqlite security update (RLSA-2024:0253) sqlite-libs-3.26.0-19.el8_9.i686.rpmLinux
sqlite security update (RLSA-2024:0253) sqlite-libs-3.26.0-19.el8_9.x86_64.rpmLinux
sqlite security update (RLSA-2024:0253) sqlite-devel-3.26.0-19.el8_9.i686.rpmLinux
sqlite security update (RLSA-2024:0253) sqlite-devel-3.26.0-19.el8_9.x86_64.rpmLinux
(RHSA-2024:0465)Moderate: security update lemon-debuginfo-3.34.1-7.el9_3.i686.rpmLinux
(RHSA-2024:0465)Moderate: security update lemon-debuginfo-3.34.1-7.el9_3.x86_64.rpmLinux
(RHSA-2024:0465)Moderate: security update sqlite-3.34.1-7.el9_3.i686.rpmLinux
(RHSA-2024:0465)Moderate: security update sqlite-3.34.1-7.el9_3.x86_64.rpmLinux
(RHSA-2024:0465)Moderate: security update sqlite-analyzer-debuginfo-3.34.1-7.el9_3.i686.rpmLinux
(RHSA-2024:0465)Moderate: security update sqlite-analyzer-debuginfo-3.34.1-7.el9_3.x86_64.rpmLinux
(RHSA-2024:0465)Moderate: security update sqlite-debuginfo-3.34.1-7.el9_3.i686.rpmLinux
(RHSA-2024:0465)Moderate: security update sqlite-debuginfo-3.34.1-7.el9_3.x86_64.rpmLinux
(RHSA-2024:0465)Moderate: security update sqlite-debugsource-3.34.1-7.el9_3.i686.rpmLinux
(RHSA-2024:0465)Moderate: security update sqlite-debugsource-3.34.1-7.el9_3.x86_64.rpmLinux
(RHSA-2024:0465)Moderate: security update sqlite-devel-3.34.1-7.el9_3.i686.rpmLinux
(RHSA-2024:0465)Moderate: security update sqlite-devel-3.34.1-7.el9_3.x86_64.rpmLinux
(RHSA-2024:0465)Moderate: security update sqlite-libs-3.34.1-7.el9_3.i686.rpmLinux
(RHSA-2024:0465)Moderate: security update sqlite-libs-3.34.1-7.el9_3.x86_64.rpmLinux
(RHSA-2024:0465)Moderate: security update sqlite-libs-debuginfo-3.34.1-7.el9_3.i686.rpmLinux
(RHSA-2024:0465)Moderate: security update sqlite-libs-debuginfo-3.34.1-7.el9_3.x86_64.rpmLinux
(RHSA-2024:0465)Moderate: security update sqlite-tcl-debuginfo-3.34.1-7.el9_3.i686.rpmLinux
(RHSA-2024:0465)Moderate: security update sqlite-tcl-debuginfo-3.34.1-7.el9_3.x86_64.rpmLinux
(RHSA-2024:0465)Moderate: security update sqlite-tools-debuginfo-3.34.1-7.el9_3.i686.rpmLinux
(RHSA-2024:0465)Moderate: security update sqlite-tools-debuginfo-3.34.1-7.el9_3.x86_64.rpmLinux
Sqlite update (ELSA-2024-0465) sqlite-3.34.1-7.el9_3.i686.rpmLinux
Sqlite update (ELSA-2024-0465) sqlite-3.34.1-7.el9_3.x86_64.rpmLinux
Sqlite-devel update (ELSA-2024-0465) sqlite-devel-3.34.1-7.el9_3.i686.rpmLinux
Sqlite-devel update (ELSA-2024-0465) sqlite-devel-3.34.1-7.el9_3.x86_64.rpmLinux
Sqlite-libs update (ELSA-2024-0465) sqlite-libs-3.34.1-7.el9_3.i686.rpmLinux
Sqlite-libs update (ELSA-2024-0465) sqlite-libs-3.34.1-7.el9_3.x86_64.rpmLinux
C library that implements an SQL database engine (USN-6566-1) libsqlite3-0_3.31.1-4ubuntu0.6_i386.debLinux
C library that implements an SQL database engine (USN-6566-1) libsqlite3-0_3.31.1-4ubuntu0.6_amd64.debLinux
C library that implements an SQL database engine (USN-6566-1) libsqlite3-0_3.37.2-2ubuntu0.3_i386.debLinux
C library that implements an SQL database engine (USN-6566-1) libsqlite3-0_3.37.2-2ubuntu0.3_amd64.debLinux
C library that implements an SQL database engine (USN-6566-1) libsqlite3-0_3.40.1-1ubuntu0.1_i386.debLinux
C library that implements an SQL database engine (USN-6566-1) libsqlite3-0_3.40.1-1ubuntu0.1_amd64.debLinux
C library that implements an SQL database engine (USN-6566-1) libsqlite3-0_3.42.0-1ubuntu0.1_i386.debLinux
C library that implements an SQL database engine (USN-6566-1) libsqlite3-0_3.42.0-1ubuntu0.1_amd64.debLinux
sqlite update (TU-CESAS-0008) sqlite-3.26.0-18.el8.i686.rpmLinux
sqlite update (TU-CESAS-0008) sqlite-3.26.0-18.el8.x86_64.rpmLinux
sqlite update (TU-CESAS-0008) sqlite-libs-3.26.0-18.el8.i686.rpmLinux
sqlite update (TU-CESAS-0008) sqlite-libs-3.26.0-18.el8.x86_64.rpmLinux
sqlite update (TU-CESAS-0008) sqlite-libs-3.34.1-7.el9.i686.rpmLinux
sqlite update (TU-CESAS-0008) sqlite-libs-3.34.1-7.el9.x86_64.rpmLinux
sqlite update (TU-CESAS-0008) sqlite-devel-3.26.0-18.el8.i686.rpmLinux
sqlite update (TU-CESAS-0008) sqlite-devel-3.26.0-18.el8.x86_64.rpmLinux
libreoffice update (TU-CESAS-0008) libreoffice-opensymbol-fonts-6.4.7.2-15.el8.noarch.rpmLinux
libreoffice update (TU-CESAS-0008) libreoffice-opensymbol-fonts-7.1.8.1-11.el9.noarch.rpmLinux
nss Security Update (ALAS-2024-2442) nss-3.90.0-2.amzn2.0.2.i686.rpmLinux
nss Security Update (ALAS-2024-2442) nss-3.90.0-2.amzn2.0.2.x86_64.rpmLinux
nss Security Update (ALAS-2024-2442) nss-devel-3.90.0-2.amzn2.0.2.x86_64.rpmLinux
nss Security Update (ALAS-2024-2442) nss-tools-3.90.0-2.amzn2.0.2.x86_64.rpmLinux
nss Security Update (ALAS-2024-2442) nss-sysinit-3.90.0-2.amzn2.0.2.x86_64.rpmLinux
nss Security Update (ALAS-2024-2442) nss-pkcs11-devel-3.90.0-2.amzn2.0.2.x86_64.rpmLinux
sqlite Security Update (ALAS-2024-490) lemon-3.40.0-1.amzn2023.0.4.x86_64.rpmLinux
sqlite Security Update (ALAS-2024-490) sqlite-3.40.0-1.amzn2023.0.4.x86_64.rpmLinux
sqlite Security Update (ALAS-2024-490) sqlite-doc-3.40.0-1.amzn2023.0.4.noarch.rpmLinux
sqlite Security Update (ALAS-2024-490) sqlite-tcl-3.40.0-1.amzn2023.0.4.x86_64.rpmLinux
sqlite Security Update (ALAS-2024-490) sqlite-libs-3.40.0-1.amzn2023.0.4.x86_64.rpmLinux
sqlite Security Update (ALAS-2024-490) sqlite-devel-3.40.0-1.amzn2023.0.4.x86_64.rpmLinux
sqlite Security Update (ALAS-2024-490) sqlite-tools-3.40.0-1.amzn2023.0.4.x86_64.rpmLinux
sqlite Security Update (ALAS-2024-490) sqlite-analyzer-3.40.0-1.amzn2023.0.4.x86_64.rpmLinux
polkit Security Update (ALAS-2024-508) polkit-0.117-11.amzn2023.0.1.x86_64.rpmLinux
polkit Security Update (ALAS-2024-508) polkit-docs-0.117-11.amzn2023.0.1.noarch.rpmLinux
polkit Security Update (ALAS-2024-508) polkit-libs-0.117-11.amzn2023.0.1.x86_64.rpmLinux
polkit Security Update (ALAS-2024-508) polkit-devel-0.117-11.amzn2023.0.1.x86_64.rpmLinux
Moderate: sqlite security update lemon-3.26.0-19.el8_9.x86_64.rpmLinux
Moderate: sqlite security update sqlite-3.26.0-19.el8_9.i686.rpmLinux
Moderate: sqlite security update sqlite-3.26.0-19.el8_9.x86_64.rpmLinux
Moderate: sqlite security update sqlite-devel-3.26.0-19.el8_9.i686.rpmLinux
Moderate: sqlite security update sqlite-devel-3.26.0-19.el8_9.x86_64.rpmLinux
Moderate: sqlite security update sqlite-doc-3.26.0-19.el8_9.noarch.rpmLinux
Moderate: sqlite security update sqlite-libs-3.26.0-19.el8_9.i686.rpmLinux
Moderate: sqlite security update sqlite-libs-3.26.0-19.el8_9.x86_64.rpmLinux
Moderate: sqlite security update sqlite-3.34.1-7.el9_3.i686.rpmLinux
Moderate: sqlite security update sqlite-3.34.1-7.el9_3.x86_64.rpmLinux
Moderate: sqlite security update sqlite-devel-3.34.1-7.el9_3.i686.rpmLinux
Moderate: sqlite security update sqlite-devel-3.34.1-7.el9_3.x86_64.rpmLinux
Moderate: sqlite security update sqlite-libs-3.34.1-7.el9_3.i686.rpmLinux
Moderate: sqlite security update sqlite-libs-3.34.1-7.el9_3.x86_64.rpmLinux
sqlite security update (RLSA-2024:0465) sqlite-libs-3.34.1-7.el9_3.x86_64.rpmLinux
sqlite security update (RLSA-2024:0465) sqlite-libs-3.34.1-7.el9_3.i686.rpmLinux
sqlite security update (RLSA-2024:0465) sqlite-devel-3.34.1-7.el9_3.x86_64.rpmLinux
sqlite security update (RLSA-2024:0465) sqlite-devel-3.34.1-7.el9_3.i686.rpmLinux
sqlite security update (RLSA-2024:0465) sqlite-3.34.1-7.el9_3.x86_64.rpmLinux
sqlite security update (RLSA-2024:0465) sqlite-3.34.1-7.el9_3.i686.rpmLinux
nss Security Update (ALAS2-2024-2442) nss-3.90.0-2.amzn2.0.2.i686.rpmLinux
nss Security Update (ALAS2-2024-2442) nss-3.90.0-2.amzn2.0.2.x86_64.rpmLinux
nss Security Update (ALAS2-2024-2442) nss-devel-3.90.0-2.amzn2.0.2.x86_64.rpmLinux
nss Security Update (ALAS2-2024-2442) nss-pkcs11-devel-3.90.0-2.amzn2.0.2.x86_64.rpmLinux
nss Security Update (ALAS2-2024-2442) nss-sysinit-3.90.0-2.amzn2.0.2.x86_64.rpmLinux
nss Security Update (ALAS2-2024-2442) nss-tools-3.90.0-2.amzn2.0.2.x86_64.rpmLinux
polkit Security Update (ALAS2023-2024-508) polkit-0.117-11.amzn2023.0.1.x86_64.rpmLinux
polkit Security Update (ALAS2023-2024-508) polkit-devel-0.117-11.amzn2023.0.1.x86_64.rpmLinux
polkit Security Update (ALAS2023-2024-508) polkit-docs-0.117-11.amzn2023.0.1.noarch.rpmLinux
polkit Security Update (ALAS2023-2024-508) polkit-libs-0.117-11.amzn2023.0.1.x86_64.rpmLinux
Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2023-7104)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234