New Debian sqlite3 3.27.2-3+deb10u3 fixes: This update addresses the following issues: 3.27.2-3+deb10u3 (Mon, 30 Sep 2024 13:28:13 +0300) * Non-maintainer upload by the ELTS Team. * CVE-2019-19244: Mishandling of sub-select that uses both DISTINCT and window functions, and also has certain ORDER BY usage * CVE-2021-36690: Expert extension segfault * CVE-2023-7104: Session extension buffer overread
--- mirror/ftp/pool/main/s/sqlite3/sqlite3_3.27.2-3+deb10u2.dsc +++ apt/ucs_5.0-0-errata5.0-9/source/sqlite3_3.27.2-3+deb10u3.dsc @@ -1,3 +1,11 @@ +3.27.2-3+deb10u3 [Mon, 30 Sep 2024 13:28:13 +0300] Adrian Bunk <bunk@debian.org>: + + * Non-maintainer upload by the ELTS Team. + * CVE-2019-19244: Mishandling of sub-select that uses both DISTINCT + and window functions, and also has certain ORDER BY usage + * CVE-2021-36690: Expert extension segfault + * CVE-2023-7104: Session extension buffer overread + 3.27.2-3+deb10u2 [Tue, 13 Sep 2022 15:15:07 +0100] Chris Lamb <lamby@debian.org>: * CVE-2020-35525: Prevent a potential null pointer deference issue in <http://piuparts.knut.univention.de/5.0-9/#4564331072552974095>
OK: bug OK: yaml OK: announce_errata OK: patch ~OK: piuparts Freexian ships dbgsym packages [5.0-9] 435e3f5fb9 Bug #57645: sqlite3 3.27.2-3+deb10u3 doc/errata/staging/sqlite3.yaml | 16 ++++++++++------ 1 file changed, 10 insertions(+), 6 deletions(-) [5.0-9] a8d88e1d3c Bug #57645: sqlite3 3.27.2-3+deb10u3 doc/errata/staging/sqlite3.yaml | 19 +++++++++++++++++++ 1 file changed, 19 insertions(+)
<https://errata.software-univention.de/#/?erratum=5.0x1140>