Scientific Linux Security Update : sqlite on SL7.x x86_64 (20150817)

high Nessus Plugin ID 85502

Synopsis

The remote Scientific Linux host is missing one or more security updates.

Description

A flaw was found in the way SQLite handled dequoting of collation-sequence names. A local attacker could submit a specially crafted COLLATE statement that would crash the SQLite process, or have other unspecified impacts. (CVE-2015-3414)

It was found that SQLite's sqlite3VdbeExec() function did not properly implement comparison operators. A local attacker could submit a specially crafted CHECK statement that would crash the SQLite process, or have other unspecified impacts. (CVE-2015-3415)

It was found that SQLite's sqlite3VXPrintf() function did not properly handle precision and width values during floating-point conversions. A local attacker could submit a specially crafted SELECT statement that would crash the SQLite process, or have other unspecified impacts.
(CVE-2015-3416)

Solution

Update the affected packages.

See Also

http://www.nessus.org/u?212022ab

Plugin Details

Severity: High

ID: 85502

File Name: sl_20150817_sqlite_on_SL7_x.nasl

Version: 2.6

Type: local

Agent: unix

Published: 8/18/2015

Updated: 1/14/2021

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: High

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:fermilab:scientific_linux:lemon, p-cpe:/a:fermilab:scientific_linux:sqlite, p-cpe:/a:fermilab:scientific_linux:sqlite-debuginfo, p-cpe:/a:fermilab:scientific_linux:sqlite-devel, p-cpe:/a:fermilab:scientific_linux:sqlite-doc, p-cpe:/a:fermilab:scientific_linux:sqlite-tcl, x-cpe:/o:fermilab:scientific_linux

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Patch Publication Date: 8/17/2015

Vulnerability Publication Date: 4/24/2015

Reference Information

CVE: CVE-2015-3414, CVE-2015-3415, CVE-2015-3416