Debian Security Advisory
DLA-1613-1 sqlite3 -- LTS security update
- Date Reported:
- 22 Dec 2018
- Affected Packages:
- sqlite3
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2018-20346.
- More information:
-
Security experts at Tencent’s Blade security team have discovered a critical vulnerability in SQLite database software (nicknamed
Magellan
).The
Magellan
remote code execution vulnerability has now been fixed by adding extra defenses against strategically corrupt databases to fts3/4.For Debian 8
Jessie
, this problem has been fixed in version 3.8.7.1-1+deb8u3.We recommend that you upgrade your sqlite3 packages.
Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS