Debian 9909 Published by

A sqlite3 security update has been released for Debian GNU/Linux 8 and 9 Extended LTS to address a potential null pointer dereference vulnerability.



ELA-678-1 sqlite3 security update

Package sqlite3
Version 3.8.7.1-1+deb8u8 (jessie), 3.16.2-5+deb9u4 (stretch)
Related CVEs CVE-2020-35525

A potential null pointer dereference vulnerability was discovered in the popular embedded database engine SQLite related to INTERSEC query processing.

For Debian 8 jessie, these problems have been fixed in version 3.8.7.1-1+deb8u8.

For Debian 9 stretch, these problems have been fixed in version 3.16.2-5+deb9u4.

We recommend that you upgrade your sqlite3 packages.

Further information about Extended LTS security advisories can be found at: https://deb.freexian.com/extended-lts/

  ELA-678-1 sqlite3 security update