Security Fix(es):
SQLite through 3.40.0, when relying on --safe for execution of an untrusted CLI script, does not properly implement the azProhibitedFunctions protection mechanism, and instead allows UDF functions such as WRITEFILE.(CVE-2022-46908)
{
"severity": "Critical"
}{
"aarch64": [
"sqlite-devel-3.37.2-4.oe2203.aarch64.rpm",
"sqlite-debuginfo-3.37.2-4.oe2203.aarch64.rpm",
"sqlite-debugsource-3.37.2-4.oe2203.aarch64.rpm",
"sqlite-3.37.2-4.oe2203.aarch64.rpm"
],
"src": [
"sqlite-3.37.2-4.oe2203.src.rpm"
],
"x86_64": [
"sqlite-debuginfo-3.37.2-4.oe2203.x86_64.rpm",
"sqlite-devel-3.37.2-4.oe2203.x86_64.rpm",
"sqlite-debugsource-3.37.2-4.oe2203.x86_64.rpm",
"sqlite-3.37.2-4.oe2203.x86_64.rpm"
],
"noarch": [
"sqlite-help-3.37.2-4.oe2203.noarch.rpm"
]
}