Bug 1085790 (CVE-2018-8740) - VUL-1: CVE-2018-8740: sqlite3, sqlite2: Databases whose schema is corrupted using a CREATE TABLE AS statement could cause a NULL pointer dereference
Summary: VUL-1: CVE-2018-8740: sqlite3, sqlite2: Databases whose schema is corrupted u...
Status: RESOLVED FIXED
Alias: CVE-2018-8740
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P4 - Low : Minor
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/202195/
Whiteboard: CVSSv3:SUSE:CVE-2018-8740:4.0:(AV:L/A...
Keywords:
Depends on:
Blocks:
 
Reported: 2018-03-19 07:18 UTC by Johannes Segitz
Modified: 2024-07-19 12:30 UTC (History)
7 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Johannes Segitz 2018-03-19 07:18:09 UTC
CVE-2018-8740

In SQLite through 3.22.0, databases whose schema is corrupted using a CREATE
TABLE AS statement could cause a NULL pointer dereference, related to build.c
and prepare.c.

sqlite2/3 everywhere affected. No reproducer

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-8740
http://seclists.org/oss-sec/2018/q1/244
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=6964
https://bugs.launchpad.net/ubuntu/+source/sqlite3/+bug/1756349
https://www.sqlite.org/cgi/src/timeline?r=corrupt-schema
https://www.sqlite.org/cgi/src/vdiff?from=1774f1c3baf0bc3d&to=d75e67654aa9620b
Comment 1 Martin Pluskal 2018-03-19 07:53:04 UTC
I am definitely bugowner for sqlite3, sqlite2 is still in TW but I guess it can be dropped.
Comment 2 Reinhard Max 2018-03-19 10:14:14 UTC
We used to keep sqlite2 for gphoto2, so that it can still read and migrate databases that were created with older versions.

Marcus, is this backwards compatibility still needed?
Comment 3 Martin Pluskal 2018-03-19 10:58:13 UTC
sqlite2 is depended on by:
libdbi-drivers-dbd-sqlite gambas3-gb-db-sqlite2
Comment 4 Marcus Meissner 2018-03-19 13:30:33 UTC
digikam uses sqlite, not gphoto2 ... ;) 

but i can try to find out
Comment 5 Marcus Meissner 2018-04-06 13:07:39 UTC
i think its not related anymore,.
Comment 12 Swamp Workflow Management 2019-05-10 19:19:49 UTC
SUSE-SU-2019:1208-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 1085790,1132045
CVE References: CVE-2017-10989,CVE-2018-8740
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP4 (src):    sqlite3-3.8.10.2-9.6.1
SUSE Linux Enterprise Software Development Kit 12-SP3 (src):    sqlite3-3.8.10.2-9.6.1
SUSE Linux Enterprise Server 12-SP4 (src):    sqlite3-3.8.10.2-9.6.1
SUSE Linux Enterprise Server 12-SP3 (src):    sqlite3-3.8.10.2-9.6.1
SUSE Linux Enterprise Desktop 12-SP4 (src):    sqlite3-3.8.10.2-9.6.1
SUSE Linux Enterprise Desktop 12-SP3 (src):    sqlite3-3.8.10.2-9.6.1
SUSE CaaS Platform ALL (src):    sqlite3-3.8.10.2-9.6.1
SUSE CaaS Platform 3.0 (src):    sqlite3-3.8.10.2-9.6.1
OpenStack Cloud Magnum Orchestration 7 (src):    sqlite3-3.8.10.2-9.6.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 13 Swamp Workflow Management 2019-05-22 01:08:51 UTC
openSUSE-SU-2019:1426-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 1085790,1132045
CVE References: CVE-2017-10989,CVE-2018-8740
Sources used:
openSUSE Leap 42.3 (src):    sqlite3-3.8.10.2-11.7.1
Comment 15 Swamp Workflow Management 2019-06-17 19:18:55 UTC
SUSE-SU-2019:1522-1: An update that fixes three vulnerabilities is now available.

Category: security (important)
Bug References: 1085790,1132045,1136976
CVE References: CVE-2017-10989,CVE-2018-8740,CVE-2019-8457
Sources used:
SUSE Linux Enterprise Server 12-LTSS (src):    sqlite3-3.8.3.1-2.12.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 20 Swamp Workflow Management 2019-11-25 20:23:44 UTC
SUSE-SU-2019:14228-1: An update that fixes two vulnerabilities is now available.

Category: security (important)
Bug References: 1085790,1155787
CVE References: CVE-2017-2518,CVE-2018-8740
Sources used:
SUSE Linux Enterprise Debuginfo 11-SP3 (src):    sqlite3-3.6.4-4.8.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 24 Andrea Mattiazzo 2024-07-19 12:30:51 UTC
All done, closing.