CVE-2022-46908

SQLite through 3.40.0, when relying on --safe for execution of an untrusted CLI script, does not properly implement the azProhibitedFunctions protection mechanism, and instead allows UDF functions such as WRITEFILE.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sqlite:sqlite:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:31

Type Values Removed Values Added
Summary
  • (es) SQLite hasta 3.40.0, cuando depende de --safe para la ejecución de un script CLI que no es de confianza, no implementa correctamente el mecanismo de protección azProhibitedFunctions y, en su lugar, permite funciones UDF como WRITEFILE.
References () https://news.ycombinator.com/item?id=33948588 - Exploit, Issue Tracking, Third Party Advisory () https://news.ycombinator.com/item?id=33948588 - Exploit, Issue Tracking, Third Party Advisory
References () https://security.gentoo.org/glsa/202311-03 - () https://security.gentoo.org/glsa/202311-03 -
References () https://security.netapp.com/advisory/ntap-20230203-0005/ - Third Party Advisory () https://security.netapp.com/advisory/ntap-20230203-0005/ - Third Party Advisory
References () https://sqlite.org/forum/forumpost/07beac8056151b2f - Exploit, Issue Tracking, Vendor Advisory () https://sqlite.org/forum/forumpost/07beac8056151b2f - Exploit, Issue Tracking, Vendor Advisory
References () https://sqlite.org/src/info/cefc032473ac5ad2 - Patch, Vendor Advisory () https://sqlite.org/src/info/cefc032473ac5ad2 - Patch, Vendor Advisory

24 Nov 2023, 14:15

Type Values Removed Values Added
References
  • () https://security.gentoo.org/glsa/202311-03 -

Information

Published : 2022-12-12 06:15

Updated : 2025-05-05 16:15


NVD link : CVE-2022-46908

Mitre link : CVE-2022-46908

CVE.ORG link : CVE-2022-46908


JSON object : View

Products Affected

sqlite

  • sqlite