os_unix.c in SQLite before 3.13.0 improperly implements the temporary directory search algorithm, which might allow local users to obtain sensitive information, cause a denial of service (application crash), or have unspecified other impact by leveraging use of the current working directory for temporary files.
References
Link | Resource |
---|---|
http://www.openwall.com/lists/oss-security/2016/07/01/1 | Patch Third Party Advisory |
http://www.securityfocus.com/bid/91546 | Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IGQTH7V45QVHFDXJAEECHEO3HHD644WZ/ | Third Party Advisory |
https://www.korelogic.com/Resources/Advisories/KL-001-2016-003.txt | Third Party Advisory |
https://www.sqlite.org/releaselog/3_13_0.html | Release Notes |
http://www.sqlite.org/cgi/src/info/67985761aa93fb61 | Vendor Advisory |
http://www.openwall.com/lists/oss-security/2016/07/01/2 | Third Party Advisory |
http://lists.opensuse.org/opensuse-updates/2016-08/msg00053.html | Third Party Advisory |
https://www.tenable.com/security/tns-2016-20 | |
https://usn.ubuntu.com/4019-1/ | |
https://usn.ubuntu.com/4019-2/ | |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PU4NZ6DDU4BEM3ACM3FM6GLEPX56ZQXK/ |
Information
Published : 2016-09-26 09:59
Updated : 2018-10-30 09:27
NVD link : CVE-2016-6153
Mitre link : CVE-2016-6153
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
sqlite
- sqlite
fedoraproject
- fedora
opensuse
- leap