A Memory Leak vulnerability exists in SQLite Project SQLite3 3.35.1 and 3.37.0 via maliciously crafted SQL Queries (made via editing the Database File), it is possible to query a record, and leak subsequent bytes of memory that extend beyond the record, which could let a malicious user obtain sensitive information. NOTE: The developer disputes this as a vulnerability stating that If you give SQLite a corrupted database file and submit a query against the database, it might read parts of the database that you did not intend or expect.
{
"binaries": [
{
"binary_name": "libsqlite-tcl",
"binary_version": "2.8.17-10ubuntu2"
},
{
"binary_name": "libsqlite0",
"binary_version": "2.8.17-10ubuntu2"
},
{
"binary_name": "libsqlite0-dev",
"binary_version": "2.8.17-10ubuntu2"
},
{
"binary_name": "sqlite",
"binary_version": "2.8.17-10ubuntu2"
}
]
}{
"binaries": [
{
"binary_name": "libsqlite-tcl",
"binary_version": "2.8.17-12fakesync1"
},
{
"binary_name": "libsqlite0",
"binary_version": "2.8.17-12fakesync1"
},
{
"binary_name": "libsqlite0-dev",
"binary_version": "2.8.17-12fakesync1"
},
{
"binary_name": "sqlite",
"binary_version": "2.8.17-12fakesync1"
}
]
}{
"binaries": [
{
"binary_name": "libsqlite-tcl",
"binary_version": "2.8.17-14fakesync1"
},
{
"binary_name": "libsqlite0",
"binary_version": "2.8.17-14fakesync1"
},
{
"binary_name": "libsqlite0-dev",
"binary_version": "2.8.17-14fakesync1"
},
{
"binary_name": "sqlite",
"binary_version": "2.8.17-14fakesync1"
}
]
}{
"binaries": [
{
"binary_name": "libsqlite-tcl",
"binary_version": "2.8.17-15fakesync1build1"
},
{
"binary_name": "libsqlite0",
"binary_version": "2.8.17-15fakesync1build1"
},
{
"binary_name": "libsqlite0-dev",
"binary_version": "2.8.17-15fakesync1build1"
},
{
"binary_name": "sqlite",
"binary_version": "2.8.17-15fakesync1build1"
}
]
}{
"binaries": [
{
"binary_name": "libsqlite-tcl",
"binary_version": "2.8.17-15fakesync1build1"
},
{
"binary_name": "libsqlite0",
"binary_version": "2.8.17-15fakesync1build1"
},
{
"binary_name": "libsqlite0-dev",
"binary_version": "2.8.17-15fakesync1build1"
},
{
"binary_name": "sqlite",
"binary_version": "2.8.17-15fakesync1build1"
}
]
}{
"binaries": [
{
"binary_name": "lemon",
"binary_version": "3.37.2-2ubuntu0.5"
},
{
"binary_name": "libsqlite3-0",
"binary_version": "3.37.2-2ubuntu0.5"
},
{
"binary_name": "libsqlite3-dev",
"binary_version": "3.37.2-2ubuntu0.5"
},
{
"binary_name": "libsqlite3-tcl",
"binary_version": "3.37.2-2ubuntu0.5"
},
{
"binary_name": "sqlite3",
"binary_version": "3.37.2-2ubuntu0.5"
},
{
"binary_name": "sqlite3-tools",
"binary_version": "3.37.2-2ubuntu0.5"
}
]
}{
"binaries": [
{
"binary_name": "lemon",
"binary_version": "3.8.2-1ubuntu2.2+esm5"
},
{
"binary_name": "libsqlite3-0",
"binary_version": "3.8.2-1ubuntu2.2+esm5"
},
{
"binary_name": "libsqlite3-dev",
"binary_version": "3.8.2-1ubuntu2.2+esm5"
},
{
"binary_name": "libsqlite3-tcl",
"binary_version": "3.8.2-1ubuntu2.2+esm5"
},
{
"binary_name": "sqlite3",
"binary_version": "3.8.2-1ubuntu2.2+esm5"
}
]
}{
"binaries": [
{
"binary_name": "lemon",
"binary_version": "3.11.0-1ubuntu1.5+esm3"
},
{
"binary_name": "libsqlite3-0",
"binary_version": "3.11.0-1ubuntu1.5+esm3"
},
{
"binary_name": "libsqlite3-dev",
"binary_version": "3.11.0-1ubuntu1.5+esm3"
},
{
"binary_name": "libsqlite3-tcl",
"binary_version": "3.11.0-1ubuntu1.5+esm3"
},
{
"binary_name": "sqlite3",
"binary_version": "3.11.0-1ubuntu1.5+esm3"
}
]
}{
"binaries": [
{
"binary_name": "lemon",
"binary_version": "3.22.0-1ubuntu0.7+esm2"
},
{
"binary_name": "libsqlite3-0",
"binary_version": "3.22.0-1ubuntu0.7+esm2"
},
{
"binary_name": "libsqlite3-dev",
"binary_version": "3.22.0-1ubuntu0.7+esm2"
},
{
"binary_name": "libsqlite3-tcl",
"binary_version": "3.22.0-1ubuntu0.7+esm2"
},
{
"binary_name": "sqlite3",
"binary_version": "3.22.0-1ubuntu0.7+esm2"
}
]
}{
"binaries": [
{
"binary_name": "lemon",
"binary_version": "3.31.1-4ubuntu0.7+esm1"
},
{
"binary_name": "libsqlite3-0",
"binary_version": "3.31.1-4ubuntu0.7+esm1"
},
{
"binary_name": "libsqlite3-dev",
"binary_version": "3.31.1-4ubuntu0.7+esm1"
},
{
"binary_name": "libsqlite3-tcl",
"binary_version": "3.31.1-4ubuntu0.7+esm1"
},
{
"binary_name": "sqlite3",
"binary_version": "3.31.1-4ubuntu0.7+esm1"
}
]
}