SQLite SQLite3 make alltest sqlite3session.c sessionReadRecord heap-based overflow
CVE-2023-7104
5.5MEDIUM
What is CVE-2023-7104?
A vulnerability exists in SQLite3 that affects the sessionReadRecord function, specifically within the ext/session/sqlite3session.c file. This vulnerability results in a heap-based buffer overflow, which could be exploited to potentially compromise the security of systems using SQLite3 up to version 3.43.0. It is highly recommended for users to apply the relevant patches to mitigate this issue effectively. For further details, including technical descriptions and patches, consult the provided references.
Affected Version(s)
SQLite3 3.0
SQLite3 3.1
SQLite3 3.2
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Junwha Hong
Wonil Jang
qbit (VulDB User)