Wind River Support Network

HomeDefectsLIN1021-4913
Fixed

LIN1021-4913 : Security Advisory - sqlite3 - CVE-2022-46908

Created: Dec 12, 2022    Updated: Dec 26, 2022
Resolved Date: Dec 26, 2022
Found In Version: 10.21.20.1
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

SQLite through 3.40.0, when relying on --safe for execution of an untrusted CLI script, does not properly imple
ment the azProhibitedFunctions protection mechanism, and instead allows UDF functions such as WRITEFILE.

CREATE(Triage):(User=admin) CVE-2022-46908 (https://nvd.nist.gov/vuln/detail/CVE-2022-46908)
Live chat
Online