REDHAT-BUG-2380149: SQL Injection
There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.50.2
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2380149?
The severity of REDHAT-BUG-2380149 is classified as medium due to potential memory corruption issues.
How do I fix REDHAT-BUG-2380149?
To fix REDHAT-BUG-2380149, upgrade to SQLite version 3.50.2 or later.
What are the risks associated with REDHAT-BUG-2380149?
Risks associated with REDHAT-BUG-2380149 include potential crashes or unpredictable behavior of applications using affected SQLite versions.
Which versions of SQLite are affected by REDHAT-BUG-2380149?
SQLite versions prior to 3.50.2 are affected by REDHAT-BUG-2380149.
Is there a workaround for REDHAT-BUG-2380149?
There is no specific workaround for REDHAT-BUG-2380149; the best solution is to upgrade to a secure version.