【安全公告:UTSA-2022-000442】-【CVE-2021-36690】

发布日期:2022-11-02

基本信息

漏洞编号: CVE-2021-36690

受影响系统版本: 服务器D版

受影响源码包: sqlite3

修复版本: 3.39.3-1

CWE编号: None

漏洞等级: 高危

CVSS_v3评分: 7.5

漏洞描述

** DISPUTED ** A segmentation fault can occur in the sqlite3.exe command-line component of SQLite 3.36.0 via the idxGetTableInfo function when there is a crafted SQL query. NOTE: the vendor disputes the relevance of this report because a sqlite3.exe user already has full privileges (e.g., is intentionally allowed to execute commands). This report does NOT imply any problem in the SQLite library.

修复方式

sudo apt update && sudo apt dist-upgrade

是否受影响判断

判断方法:apt policy PackageName
结果说明:版本小于修复版本,则受此漏洞影响,版本大于等于修复版本,则此漏洞已修复。

补丁链接

暂无