Resource management error in SQLite - CVE-2016-6153

 

Resource management error in SQLite - CVE-2016-6153

Published: September 4, 2019


Vulnerability identifier: #VU20866
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-6153
CWE-ID: CWE-399
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack or gain access to sensitive information.

The vulnerability exists due to the application improperly implements the temporary directory search algorithm. A local user can make the application use the current working directory for storing temporary files and gain access to sensitive information or perform denial of service attack.


Affected software

SQLite
EMC Integrated Data Protection Appliance
sqlite3 (Ubuntu package)
sqlite
mingw-sqlite
libsqlite3-0
libsqlite3-0-32bit
libsqlite3-0-debuginfo
libsqlite3-0-debuginfo-32bit
sqlite3
sqlite3-debuginfo
sqlite3-debugsource
sqlite3-devel
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
Fedora
Dell EMC Data Protection Search
Dell PowerProtect Cyber Recovery

How to mitigate CVE-2016-6153

Install updates from vendor's website.

SQLite - update to 3.13.0
EMC Integrated Data Protection Appliance - update to 2.7.1
sqlite3 (Ubuntu package) - addressed in versions 3.11.0-1ubuntu1.2, 3.22.0-1ubuntu0.1, 3.24.0-1ubuntu0.1, 3.27.2-2ubuntu0.1
Dell EMC Data Protection Search - update to 19.6.0
sqlite - update to 3.13.0-1.fc24
mingw-sqlite - update to 3.26.0.0-1.fc29
libsqlite3-0 - update to 3.36.0-9.18.1
libsqlite3-0-32bit - update to 3.36.0-9.18.1
libsqlite3-0-debuginfo - update to 3.36.0-9.18.1
libsqlite3-0-debuginfo-32bit - update to 3.36.0-9.18.1
sqlite3 - update to 3.36.0-9.18.1
sqlite3-debuginfo - update to 3.36.0-9.18.1
sqlite3-debugsource - update to 3.36.0-9.18.1
sqlite3-devel - update to 3.36.0-9.18.1
Dell PowerProtect Cyber Recovery - update to 18.1.1.2-8

External References

Related Security Bulletins