os_unix.c in SQLite before 3.13.0 improperly implements the temporary directory search algorithm, which might allow local users to obtain sensitive information, cause a denial of service (application crash), or have unspecified other impact by leveraging use of the current working directory for temporary files.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Itunes | apple-itunes-upgrade-latest | Mar 24, 2017 | Sep 26, 2016 | |
| Debian | debian-upgrade-sqlite3 | Mar 31, 2017 | Jul 5, 2016 | |
| Freebsd | freebsd-upgrade-package-sqlite3 | Dec 10, 2025 | Jul 3, 2016 | |
| Huawei Euleros 2_0_sp2 | huawei-euleros-2_0_sp2-upgrade-sqlitehuawei-euleros-2_0_sp2-upgrade-sqlite-devel | Dec 4, 2019 | Sep 26, 2016 | |
| Huawei Euleros 2_0_sp3 | huawei-euleros-2_0_sp3-upgrade-sqlitehuawei-euleros-2_0_sp3-upgrade-sqlite-devel | Dec 18, 2019 | Sep 26, 2016 | |
| Huawei Euleros 2_0_sp5 | huawei-euleros-2_0_sp5-upgrade-sqlitehuawei-euleros-2_0_sp5-upgrade-sqlite-devel | Sep 24, 2019 | Sep 26, 2016 | |
| Oracle Solaris | oracle-solaris-11-4-upgrade-entire-11-4-11-4-0-0-1-15-0 | Oct 19, 2018 | Sep 26, 2016 | |
| Redhat_linux | — | no-fix-redhat-rpm-package | Jul 9, 2025 | Jul 1, 2016 |
| Suse | — | suse-upgrade-libsqlite3-0suse-upgrade-libsqlite3-0-32bitsuse-upgrade-libsqlite3-0-x86suse-upgrade-sqlite3suse-upgrade-sqlite3-devel | Sep 26, 2016 | Sep 26, 2016 |
| Ubuntu | ubuntu-pro-upgrade-libsqlite3-0ubuntu-pro-upgrade-sqlite3ubuntu-upgrade-libsqlite3-0ubuntu-upgrade-sqlite3 | Jun 20, 2019 | Sep 26, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub