Debian Security Advisory

DLA-1018-1 sqlite3 -- LTS security update

Date Reported:
09 Jul 2017
Affected Packages:
sqlite3
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2017-10989.
More information:

It was discovered that there was a heap-based buffer over-read vulnerability in SQLite, a lightweight database engine. The getNodeSize function in ext/rtree/rtree.c mishandled undersized RTree blobs in a specially-crafted database,

For Debian 7 Wheezy, this issue has been fixed in sqlite3 version 3.7.13-1+deb7u4.

We recommend that you upgrade your sqlite3 packages.