VDB
Sign up
HIGH7.5

GHSA-jw36-hf63-69r9

`libsqlite3-sys` via C SQLite improperly validates array index

Details

SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/libsqlite3-sys
Introduced in: 0Fixed in: 0.25.1

Upgrade libsqlite3-sys to 0.25.1 or newer (ecosystem crates.io).

References