Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SQLite 3.30.1 #323

Closed
Filip01011010 opened this issue Jan 3, 2020 · 13 comments
Closed

SQLite 3.30.1 #323

Filip01011010 opened this issue Jan 3, 2020 · 13 comments

Comments

@Filip01011010
Copy link

Filip01011010 commented Jan 3, 2020

Currently used version of SQLite has a known vulnerability. Could you please upgrade SQLite to version above 3.30.1?

@ericsink
Copy link
Owner

ericsink commented Jan 3, 2020

Will do.

@aloknakate84
Copy link

Hi Eric, Any update on the SQlite 3.30.1?

@ericsink
Copy link
Owner

ericsink commented Jan 8, 2020

I can assure you that when there is an update, it will be visible here in this issue.

I haven't gotten this done yet. Soon.

@ericsink
Copy link
Owner

ericsink commented Jan 9, 2020

I assume you are talking about the so-called "Magellan 2.0" stuff from Tencent.

FWIW, the author of SQLite posted something on the sqlite-users mailing list yesterday giving his opinion about the urgency (or lack of same) on this issue.

Anyway, regardless of whether these vulnerabilities are urgent or not, as far as I can tell, 3.30.1 does not actually contain a patch for them.

@Filip01011010
Copy link
Author

According to https://nvd.nist.gov/vuln/detail/CVE-2019-19646
criticality level is pretty high: "Base Score: 9.8 CRITICAL"

@ericsink
Copy link
Owner

ericsink commented Jan 9, 2020

I'm not interested in arguing about how critical this is or is not. The fact remains, there is AFAICT no SQLite release which contains a fix.

@Filip01011010
Copy link
Author

No arguing here. I missed the fact that 3.30.1 was also affected

@bricelam
Copy link
Contributor

bricelam commented Apr 7, 2020

I'm eager to use the following features:

@ericsink
Copy link
Owner

ericsink commented Apr 7, 2020

In progress at #340

@ericsink
Copy link
Owner

ericsink commented May 1, 2020

v2.0.3 has been pushed to nuget. Its e_sqlite3 bulds are at 3.31.1.

@ericsink ericsink mentioned this issue May 1, 2020
@tranb3r
Copy link

tranb3r commented May 3, 2020

It seems like sqlcipher is still 4.2.0 (based on sqlite 3.28.0).
Are you planning to upgrade it to 4.3.0 (based on sqlite 3.30.1) ?

@ericsink
Copy link
Owner

ericsink commented May 3, 2020

Yes, probably.

(The e_sqlcipher builds are unofficial and unsupported, and I update them less frequently. I typically recommend that folks buy official builds from Zetetic. )

@tranb3r
Copy link

tranb3r commented Oct 22, 2020

@ericsink
sqlcipher 4.4.0 (based on sqlite 3.31.0) was released a few months ago.
Are you planning an update ?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants