Full Disclosure mailing list archives
Re: several issues in SQLite (+ catching up on several other bugs)
From: Hanno Böck <hanno () hboeck de>
Date: Thu, 16 Apr 2015 13:16:16 +0200
Hi, Nice work. I took the latest release and ran the fuzzer again (without all the dictionary and special testcase stuff, may re-do that later). Uncovered two more issues, one in the statement parser causing an off-by-one read with the 2 byte input ".\": https://www.sqlite.org/cgi/src/info/e018f4bf1f27f783 And one in the parser of the database binary format itself: https://www.sqlite.org/cgi/src/info/f71053cf658b3260 (not sure if there is any plausible attack scenario) Both "only" invalid memory reads, so likely nothing to worry. Just a motivation for others to fuzz again, there may be more to find. Thanks also to Richard for fixing both issues very quickly. cu, -- Hanno Böck http://hboeck.de/ mail/jabber: hanno () hboeck de GPG: BBB51E42
Attachment:
_bin
Description: OpenPGP digital signature
_______________________________________________ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/
Current thread:
- several issues in SQLite (+ catching up on several other bugs) Michal Zalewski (Apr 14)
- Re: several issues in SQLite (+ catching up on several other bugs) Paul Vixie (Apr 14)
- Re: several issues in SQLite (+ catching up on several other bugs) Hanno Böck (Apr 16)
- Re: several issues in SQLite (+ catching up on several other bugs) jungle Boogie (Apr 19)
- Re: several issues in SQLite (+ catching up on several other bugs) Michal Zalewski (Apr 19)
- Re: several issues in SQLite (+ catching up on several other bugs) jungle Boogie (Apr 19)
- Re: several issues in SQLite (+ catching up on several other bugs) Jeffrey Walton (Apr 19)
- Re: several issues in SQLite (+ catching up on several other bugs) Michal Zalewski (Apr 19)
- Re: several issues in SQLite (+ catching up on several other bugs) Jeffrey Walton (Apr 19)
- Re: several issues in SQLite (+ catching up on several other bugs) Michal Zalewski (Apr 19)
- Re: several issues in SQLite (+ catching up on several other bugs) Reed Loden (Apr 20)