CVE-2022-46908
Summary
| CVE | CVE-2022-46908 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-12-12 06:15:00 UTC |
| Updated | 2023-11-24 14:15:00 UTC |
| Description | SQLite through 3.40.0, when relying on --safe for execution of an untrusted CLI script, does not properly implement the azProhibitedFunctions protection mechanism, and instead allows UDF functions such as WRITEFILE. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Just a few days ago I found a serious security issue in SQLite: https://sqlite.o... | Hacker News | MISC | news.ycombinator.com | |
| SQLite: Multiple Vulnerabilities (GLSA 202311-03) — Gentoo security | security.gentoo.org | ||
| CVE-2022-46908 SQLite Vulnerability in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| SQLite Forum: Why does --safe not prevent writefile() and readfile()? | MISC | sqlite.org | |
| SQLite: Check-in [cefc0324] | MISC | sqlite.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 184470 Debian Security Update for sqlite3 (CVE-2022-46908)
- 200023 Ubuntu Security Notification for SQLite Vulnerabilities (USN-6566-1)
- 296099 Oracle Solaris 11.4 Support Repository Update (SRU) 57.144.3 Missing (CPUAPR2023)
- 672848 EulerOS Security Update for sqlite (EulerOS-SA-2023-1578)
- 672849 EulerOS Security Update for sqlite (EulerOS-SA-2023-1588)
- 710786 Gentoo Linux SQLite Multiple Vulnerabilities (GLSA 202311-03)
- 753057 SUSE Enterprise Linux Security Update for sqlite3 (SUSE-SU-2022:4603-1)
- 753072 SUSE Enterprise Linux Security Update for sqlite3 (SUSE-SU-2022:4628-1)
- 754146 SUSE Enterprise Linux Security Update for sqlite3 (SUSE-SU-2023:2668-1)
- 754149 SUSE Enterprise Linux Security Update for sqlite3 (SUSE-SU-2023:1295-1)
- 904672 Common Base Linux Mariner (CBL-Mariner) Security Update for sqlite (11592)
- 904675 Common Base Linux Mariner (CBL-Mariner) Security Update for sqlite (11586)
- 904711 Common Base Linux Mariner (CBL-Mariner) Security Update for sqlite (11586-1)