Publishing details

Changelog

sqlite3 (3.8.7.4-1ubuntu0.1) vivid-security; urgency=medium

  * SECURITY UPDATE: improper dequoting of collation-sequence names
    - debian/patches/CVE-2015-3414.patch: handle dequoting in src/expr.c,
      src/parse.y, src/sqliteInt.h, src/where.c, added tests to
      test/collate1.test.
    - CVE-2015-3414
  * SECURITY UPDATE: improper implementation of comparison operators
    - debian/patches/CVE-2015-3415.patch: properly handle MEM_Dyn flag on
      registers in src/vdbe.c.
    - CVE-2015-3415
  * SECURITY UPDATE: improper large integers handling in printf function
    - debian/patches/CVE-2015-3416.patch: handle large integers in
      src/printf.c, added tests to test/printf.test.
    - CVE-2015-3416

 -- Marc Deslauriers <email address hidden>  Tue, 14 Jul 2015 12:58:38 -0400

Available diffs

Builds

Package files