vulnerability

FreeBSD: SQLite3 -- Tempdir Selection Vulnerability (CVE-2016-6153)

Severity
4
CVSS
(AV:L/AC:L/Au:N/C:P/I:P/A:P)
Published
Jul 1, 2016
Added
Jul 4, 2016
Modified
Oct 30, 2017

Description



KoreLogic security reports:

Affected versions of SQLite reject potential tempdir locations if
they are not readable, falling back to '.'. Thus, SQLite will favor
e.g. using cwd for tempfiles on such a system, even if cwd is an
unsafe location. Notably, SQLite also checks the permissions of
'.', but ignores the results of that check.

Solution

freebsd-upgrade-package-sqlite3
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.