quaint icon indicating copy to clipboard operation
quaint copied to clipboard

Security alert [severity high] - `libsqlite3-sys` via C SQLite improperly validates array index

Open carlos-rian opened this issue 2 years ago • 0 comments

The latest possible version of libsqlite3-sys that can be installed is 0.22.2.

The earliest fixed version is 0.25.1.

image

SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.

carlos-rian avatar Apr 24 '23 18:04 carlos-rian