Bug #77541 [Csd->Dup]: SQLite < 3.26.0 - Possible magellan vulnerability
| From: | cmb@php.net | Date: | Tue, 29 Jan 2019 16:36:24 +0000 |
| Subject: | Bug #77541 [Csd->Dup]: SQLite < 3.26.0 - Possible magellan vulnerability | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-219274@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77541&edit=1
ID: 77541
Updated by: cmb@php.net
Reported by: myskina at gmail dot com
Summary: SQLite < 3.26.0 - Possible magellan vulnerability
-Status: Closed
+Status: Duplicate
Type: Bug
Package: PDO SQLite
Operating System: Windows 7 x64
PHP Version: 7.3.1
Assigned To: cmb
Block user comment: N
Private report: N
Previous Comments:
------------------------------------------------------------------------
[2019-01-29 16:30:22] myskina at gmail dot com
Oh. I didn't find the other bug report when I searched for related issues before submitting.
I'll close this one.
------------------------------------------------------------------------
[2019-01-29 16:16:43] cmb@php.net
This is basically a duplicate of bug #77305.
------------------------------------------------------------------------
[2019-01-29 15:36:28] myskina at gmail dot com
Description:
------------
This vulnerability in SQLite has been discussed on some sites:
https://thehackernews.com/2018/12/sqlite-vulnerability.html
https://www.securityweek.com/code-execution-flaw-sqlite-affects-chrome-other-software
https://news.ycombinator.com/item?id=18686305
https://nakedsecurity.sophos.com/2018/12/19/sqlite-creator-fires-back-at-tencents-bug-hunters/
PHP version 7.3.1's pdo_sqlite currently uses SQLite 3.24.0.
According to SQLite's creator to be able to use this vulnerability, you need a combination of
things. You have to be able to execute arbitrary SQL and you have to have FTS3 enabled, and in those
cases you can get a remote code execution.
Is SQLite in PHP 7.3.1 available with FTS3 on some OS?
Is PHP vulnerable?
Is an update to a version of SQLite that is at least 3.26.0 or earlier needed or planned in a future
release?
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=77541&edit=1