SQLite vulnerability

Robert Simmons rsimmons0 at gmail.com
Mon Dec 17 08:31:37 UTC 2018


https://mikemcquaid.com/2018/03/19/open-source-maintainers-owe-you-nothing/

On Sun, Dec 16, 2018, 16:42 Roger Marquis <marquis at roble.com wrote:

> Thanks to Chrome{,ium} a recently discovered SQLite exploit has been all
> over the news for a week now.  It is patched on all Linux platforms but
> has not yet shown up in FreeBSD's vulxml database.  Does this mean:
>
>   A) FreeBSD versions prior to 3.26.0 are not vulnerable, or
>
>   B) the ports-secteam is not able to properly maintain the vulnerability
>   database?
>
> If the latter perhaps someone from the security team could let us know
> how such a significant vulnerability could go unflagged for so long and,
> more importantly, what might be done to address the gap in reporting?
>
> Roger Marquis
> _______________________________________________
> freebsd-security at freebsd.org mailing list
> https://lists.freebsd.org/mailman/listinfo/freebsd-security
> To unsubscribe, send any mail to "freebsd-security-unsubscribe at freebsd.org
> "
>


More information about the freebsd-security mailing list