ext/misc/zipfile.c in SQLite 3.30.1 mishandles certain uses of INSERT INTO in situations involving embedded '\0' characters in filenames, leading to a memory-management error that can be detected by (for example) valgrind.
{
"binaries": [
{
"binary_name": "lemon",
"binary_version": "3.22.0-1ubuntu0.3"
},
{
"binary_name": "libsqlite3-0",
"binary_version": "3.22.0-1ubuntu0.3"
},
{
"binary_name": "libsqlite3-dev",
"binary_version": "3.22.0-1ubuntu0.3"
},
{
"binary_name": "libsqlite3-tcl",
"binary_version": "3.22.0-1ubuntu0.3"
},
{
"binary_name": "sqlite3",
"binary_version": "3.22.0-1ubuntu0.3"
}
],
"availability": "No subscription required"
}