{"id":"BIT-sqlite-2023-7104","summary":"SQLite SQLite3 make alltest sqlite3session.c sessionReadRecord heap-based overflow","details":"A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionReadRecord of the file ext/session/sqlite3session.c of the component make alltest Handler. The manipulation leads to heap-based buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-248999.","aliases":["CVE-2023-7104"],"modified":"2025-11-06T13:25:46.476Z","published":"2024-03-06T11:05:41.196Z","database_specific":{"severity":"High","cpes":["cpe:2.3:a:sqlite:sqlite:*:*:*:*:*:*:*:*"]},"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AYONA2XSNFMXLAW4IHLFI5UVV3QRNG5K/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D6C2HN4T2S6GYNTAUXLH45LQZHK7QPHP/"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20240112-0008/"},{"type":"WEB","url":"https://sqlite.org/forum/forumpost/5bcbf4571c"},{"type":"WEB","url":"https://sqlite.org/src/info/0e4e7a05c4204b47"},{"type":"WEB","url":"https://vuldb.com/?ctiid.248999"},{"type":"WEB","url":"https://vuldb.com/?id.248999"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-7104"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/09/msg00050.html"}],"affected":[{"package":{"name":"sqlite","ecosystem":"Bitnami","purl":"pkg:bitnami/sqlite"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.43.1"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/sqlite/BIT-sqlite-2023-7104.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"}]}],"schema_version":"1.7.3"}