CVE-2015-3414

Publication date 24 April 2015

Last updated 24 July 2024


Ubuntu priority

SQLite before 3.8.9 does not properly implement the dequoting of collation-sequence names, which allows context-dependent attackers to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other impact via a crafted COLLATE clause, as demonstrated by COLLATE"""""""" at the end of a SELECT statement.

Status

Package Ubuntu Release Status
sqlite 15.04 vivid
Not affected
14.10 utopic
Not affected
14.04 LTS trusty
Not affected
12.04 LTS precise
Not affected
10.04 LTS lucid
Not affected
sqlite3 15.04 vivid
Fixed 3.8.7.4-1ubuntu0.1
14.10 utopic Ignored end of life
14.04 LTS trusty
Fixed 3.8.2-1ubuntu2.1
12.04 LTS precise
Not affected
10.04 LTS lucid Ignored end of life

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
sqlite3

References

Related Ubuntu Security Notices (USN)

Other references