Security features bypass in SQLite - CVE-2022-46908

 

Security features bypass in SQLite - CVE-2022-46908

Published: December 28, 2022 / Updated: June 29, 2023


Vulnerability identifier: #VU70528
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-46908
CWE-ID: CWE-254
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to improper implementation of the azProhibitedFunctions protection mechanism, which allows UDF functions such as WRITEFILE when relying on --safe for execution of an untrusted CLI script. A local user can escalate privileges on the system.


Affected software

SQLite
Dell Data Protection Central
Dell EMC PowerProtect Data Protection
Oracle Communications Network Charging and Control
ObjectScale
EMC ECS
EMC Cloud Tiering Appliance
Gentoo Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
openSUSE Leap Micro
SUSE Enterprise Storage
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
Oracle Solaris
SUSE Linux Enterprise Server 12 SP2 BCL
SUSE Linux Enterprise Server 12 SP4 ESPOS
SUSE Linux Enterprise Server 12 SP4 LTSS
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Desktop
openSUSE Leap
Ubuntu
openEuler
Oracle Healthcare Translational Research
Oracle Communications Convergent Charging Controller
MySQL Workbench
Oracle Financial Services Compliance Studio
IBM Data Risk Manager
Oracle Outside In Technology
TeleControl Server Basic
Dell EMC Container Storage Modules
libsqlite3-0 (Ubuntu package)
sqlite-devel
sqlite
sqlite-debuginfo
sqlite-debugsource
sqlite-help
sqlite3-debugsource
libsqlite3-0-debuginfo
sqlite3-tcl
libsqlite3-0
sqlite3-debuginfo
sqlite3
sqlite3-devel
libsqlite3-0-32bit
libsqlite3-0-debuginfo-32bit
sqlite3-doc
libsqlite3-0-32bit-debuginfo
dev-db/sqlite
EMC ViPR SRM
Dell EMC Storage Monitoring and Reporting (SMR)
Dell Secure Connect Gateway
PowerScale OneFS

How to mitigate CVE-2022-46908

Install updates from vendor's website.

SQLite - update to 3.40.1
MySQL Workbench - update to 8.0.36
ObjectScale - update to 1.4.0
Dell EMC Container Storage Modules - update to 1.6.0
IBM Data Risk Manager - update to 2.0.6.16
TeleControl Server Basic - update to 3.1.2
EMC ECS - update to 3.8.0.4
libsqlite3-0 (Ubuntu package) - addressed in versions 3.31.1-4ubuntu0.6, 3.37.2-2ubuntu0.3, 3.40.1-1ubuntu0.1, 3.42.0-1ubuntu0.1
sqlite-devel - addressed in versions 3.37.2-4, 3.37.2-5
sqlite - addressed in versions 3.37.2-4, 3.37.2-5
sqlite-debuginfo - addressed in versions 3.37.2-4, 3.37.2-5
sqlite-debugsource - addressed in versions 3.37.2-4, 3.37.2-5
sqlite-help - addressed in versions 3.37.2-4, 3.37.2-5
sqlite3-debugsource - addressed in versions 3.39.3-9.26.1, 3.39.3-150000.3.20.1
libsqlite3-0-debuginfo - addressed in versions 3.39.3-9.26.1, 3.39.3-150000.3.20.1
sqlite3-tcl - addressed in versions 3.39.3-9.26.1, 3.39.3-150000.3.20.1
libsqlite3-0 - addressed in versions 3.39.3-9.26.1, 3.39.3-150000.3.20.1
sqlite3-debuginfo - addressed in versions 3.39.3-9.26.1, 3.39.3-150000.3.20.1
sqlite3 - addressed in versions 3.39.3-9.26.1, 3.39.3-150000.3.20.1
sqlite3-devel - addressed in versions 3.39.3-9.26.1, 3.39.3-150000.3.20.1
libsqlite3-0-32bit - addressed in versions 3.39.3-9.26.1, 3.39.3-150000.3.20.1
libsqlite3-0-debuginfo-32bit - update to 3.39.3-9.26.1
sqlite3-doc - update to 3.39.3-150000.3.20.1
libsqlite3-0-32bit-debuginfo - update to 3.39.3-150000.3.20.1
dev-db/sqlite - update to 3.42.0
EMC ViPR SRM - update to 4.9.0.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.9.0.0
Dell Secure Connect Gateway - update to 5.14.00.16
PowerScale OneFS - update to 9.4.0.14
EMC Cloud Tiering Appliance - addressed in versions 13.1.0.2.33, 13.2.0.2.24

External References

Related Security Bulletins