Heap-based buffer overflow in SQLite - CVE-2017-10989
Published: May 22, 2019
Vulnerability details
The vulnerability allows a local user to crash the application or gain access to sensitive data.
The vulnerability exists due to a boundary error in the getNodeSize() function in ext/rtree/rtree.c when handling undersized RTree blobs. A local user can supply a specially crafted database to the affected application, trigger heap-based out of bounds read and crash the application or gain access to sensitive data.
Affected software
Telemetry Dashboard
Liquidware
Citrix Workspace App
Webex App VDI
EMC ECS
Dell PowerProtect Cyber Recovery
EMC Integrated Data Protection Appliance
sqlite (Alpine package)
sqlite3 (Ubuntu package)
sqlite
sqlite3
libsqlite3-0
libsqlite3-0-32bit
libsqlite3-0-debuginfo
sqlite3-devel
sqlite3-debugsource
sqlite3-debuginfo
libsqlite3-0-debuginfo-32bit
spatialite-tools
SUSE OpenStack Cloud
HPE Helion Openstack
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
Fedora
Opensuse
Cisco Jabber
Dell EMC Data Protection Search
Cisco Webex Meetings
VMware Horizon Client
How to mitigate CVE-2017-10989
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
EMC Integrated Data Protection Appliance - update to 2.7.1
sqlite (Alpine package) - update to 3.20.1-r0
sqlite3 (Ubuntu package) - addressed in versions 3.11.0-1ubuntu1.2, 3.22.0-1ubuntu0.1, 3.24.0-1ubuntu0.1, 3.27.2-2ubuntu0.1
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Dell EMC Data Protection Search - update to 19.6.0
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
EMC ECS - update to 3.5.0.1
sqlite - addressed in versions 3.13.0-2.fc24, 3.14.2-2.fc25, 3.19.3-1.fc26
sqlite3 - update to 3.36.0-9.18.1
libsqlite3-0 - update to 3.36.0-9.18.1
libsqlite3-0-32bit - update to 3.36.0-9.18.1
libsqlite3-0-debuginfo - update to 3.36.0-9.18.1
sqlite3-devel - update to 3.36.0-9.18.1
sqlite3-debugsource - update to 3.36.0-9.18.1
sqlite3-debuginfo - update to 3.36.0-9.18.1
libsqlite3-0-debuginfo-32bit - update to 3.36.0-9.18.1
spatialite-tools - update to 4.3.0-23.fc26
Dell PowerProtect Cyber Recovery - update to 18.1.1.2-8
External References
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00050.html
- http://marc.info/?l=sqlite-users&m=149933696214713&w=2
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- http://www.securityfocus.com/bid/99502
- http://www.securitytracker.com/id/1039427
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=2405
- https://bugs.launchpad.net/ubuntu/+source/sqlite3/+bug/1700937
- https://lists.debian.org/debian-lts-announce/2019/01/msg00009.html
- https://sqlite.org/src/info/66de6f4a
- https://sqlite.org/src/vpatch?from=0db20efe201736b3&to=66de6f4a9504ec26
- https://support.apple.com/HT208112
- https://support.apple.com/HT208113
- https://support.apple.com/HT208115
- https://support.apple.com/HT208144
Related Security Bulletins
- OpenSUSE Linux update for sqlite3
- Ubuntu update for SQLite
- Heap-based buffer overflow in sqlite (Alpine package)
- Multiple vulnerabilities in Dell EMC Integrated Data Protection Appliance
- Multiple vulnerabilities in Dell EMC Data Protection Search
- SUSE update for sqlite3
- Multiple vulnerabilities in Dell EMC ECS
- Multiple vulnerabilities in Dell EMC Cyber Recovery
- Multiple vulnerabilities in Dell ThinOS
- Fedora 25 update for sqlite
- Fedora 24 update for sqlite
- Fedora 26 update for spatialite-tools, sqlite