Forum Moderators: open

Message Too Old, No Replies

remote-code execution hole in SQLite

Don't panic, just patch now

         

tangor

5:52 am on May 11, 2019 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Talos published a walkthrough, complete with examples of code highlighting precisely what the vuln is and how it exists. The fix is easy, up to a point: update your project or product to SQLite version 3.28, available on the SQLite website – and then roll out the fix to your end users.
[theregister.co.uk...]

As always, maintain the latest updates possible.

graeme_p

9:03 am on May 11, 2019 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Its not major for most of us because you would need access to the DB or and SQL injection vulenratbility to exploit it.

The biggest problem is desktop and mobile apps updating, not websites,