{"id":2115,"date":"2020-05-28T16:28:29","date_gmt":"2020-05-28T21:28:29","guid":{"rendered":"https:\/\/cert.pa\/?p=2115"},"modified":"2020-05-28T16:28:40","modified_gmt":"2020-05-28T21:28:40","slug":"csirt-panama-aviso-2020-05-27-sqlite-actualizaciones-de-multiples-vulnerabilidades-que-afectan-al-sistema-de-gestion-de-bases-de-datos-relacionales","status":"publish","type":"post","link":"https:\/\/cert.pa\/?p=2115","title":{"rendered":"CSIRT Panam\u00e1 Aviso 2020-05-27 SQLite: Actualizaciones de M\u00faltiples vulnerabilidades que afectan al sistema de gesti\u00f3n de bases de datos relacionales."},"content":{"rendered":"\n<p>Gravedad:Media&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Vulnerabilidad: CVE-2020-13434 \/ CVE-2020-13435&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Fecha\nde publicaci\u00f3n: Mayo 27, 2020<br>\n\u00daltima revisi\u00f3n: Mayo 27, 2020<br>\nPortal: https:\/\/sqlite.org<\/p>\n\n\n\n<p><strong>Sistemas Afectados:<\/strong><br>\nVulnerabilidad: CVE-2020-13434<\/p>\n\n\n\n<p>Vulnerabilidades de seguridad que afectan a todas\nlas versiones de SQLite desde que la funci\u00f3n \u201cprintf()\u201d fue introducida en la\nversi\u00f3n 3.8.2 (03-02-2014).<\/p>\n\n\n\n<p>Vulnerabilidad:\nCVE-2020-13435<\/p>\n\n\n\n<p>Vulnerabilidades de seguridad que afectan a todas\nlas versiones de SQLite desde la versi\u00f3n 3.0.<\/p>\n\n\n\n<p><strong>I. Descripci\u00f3n<\/strong><br>\nActualizaci\u00f3n de seguridad que afecta al sistema de gesti\u00f3n de bases de datos\nrelacionales SQLite.<\/p>\n\n\n\n<p><strong>II. Impacto<\/strong><\/p>\n\n\n\n<p>Vulnerabilidad: CVE-2020-13434<\/p>\n\n\n\n<p>Debido a un error de\ndesbordamiento de enteros en memoria en la funci\u00f3n \u201csqlite3_str_vappendf()\u201d en\n\u201cprintf.c\u201d, un atacante remoto podr\u00eda entregarle datos especialmente dise\u00f1ados\na la aplicaci\u00f3n, enviar el error en memoria y causar una denegaci\u00f3n de\nservicios en el sistema afectado.<\/p>\n\n\n\n<p>Vulnerabilidad:\nCVE-2020-13435<\/p>\n\n\n\n<p>Debido a la insuficiente\nvalidaci\u00f3n de datos ingresados por el usuario en la funci\u00f3n\n\u201csqlite3ExprCodeTarget()\u201d en \u201cexpr.c\u201d, un atacante remoto podr\u00eda entregarle\ndatos especialmente dise\u00f1ados a la aplicaci\u00f3n para causar una denegaci\u00f3n de\nservicios en el sistema afectado.<\/p>\n\n\n\n<p><strong>III. Referencia a soluciones, herramientas e\ninformaci\u00f3n<\/strong><strong><\/strong><\/p>\n\n\n\n<p>Actualizar a las versiones correspondientes de versi\u00f3n\n3.33.0 de SQLite, mediante su sitio web (https:\/\/sqlite.org\/download.html)<\/p>\n\n\n\n<p><strong>Fuentes:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Common Vulnerabilities and Exposures (CVE).\nRecopilado en: &nbsp;https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2020-134354<\/li><li>Common Vulnerabilities and Exposures (CVE).\nRecopilado en: <a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2020-9484\">&nbsp;https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2020-13435<\/a><\/li><li>SQLite Source Repository. Recopilado en: &nbsp;<a href=\"https:\/\/www.sqlite.org\/src\/info\/23439ea582241138\">https:\/\/www.sqlite.org\/src\/info\/23439ea582241138<\/a><\/li><li>SQLite Source Repository. Recopilado en: &nbsp;https:\/\/www.sqlite.org\/src\/info\/7a5279a25c57adf1<\/li><li>CSIRT Chile. 26 de mayo del 2020. Vulnerabilidades.\nRecopilado en: https:\/\/www.csirt.gob.cl\/vulnerabilidades\/9vsa20-00226-01\/<\/li><\/ul>\n\n\n\n<p><strong>Informaci\u00f3n de contacto<\/strong><br>\nCSIRT PANAMA<br>\nComputer Security Incident Response Team Autoridad Nacional para la Innovacion\nGubernamental<br>\nE-Mail: info@cert.pa<br>\nPhone: +507 520-CERT (2378)<br>\nWeb: https:\/\/cert.pa<br>\nTwitter: @CSIRTPanama<br>\nKey ID: 16F2B124<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Gravedad:Media&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Vulnerabilidad: CVE-2020-13434 \/ CVE-2020-13435&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Fecha de publicaci\u00f3n: Mayo 27, 2020 \u00daltima revisi\u00f3n: Mayo 27, 2020 Portal: https:\/\/sqlite.org Sistemas Afectados: Vulnerabilidad: CVE-2020-13434 Vulnerabilidades de seguridad que afectan a todas las versiones de SQLite desde que&#8230;<\/p>\n","protected":false},"author":4,"featured_media":2116,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"footnotes":""},"categories":[4],"tags":[],"class_list":["post-2115","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-avisos-de-seguridad"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/posts\/2115","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2115"}],"version-history":[{"count":1,"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/posts\/2115\/revisions"}],"predecessor-version":[{"id":2117,"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/posts\/2115\/revisions\/2117"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/media\/2116"}],"wp:attachment":[{"href":"https:\/\/cert.pa\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2115"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2115"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2115"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}