package/sqlite: security bump to version 3.25.3
authorPeter Korsgaard <peter@korsgaard.com>
Sat, 22 Dec 2018 07:44:47 +0000 (08:44 +0100)
committerThomas Petazzoni <thomas.petazzoni@bootlin.com>
Sun, 30 Dec 2018 21:41:29 +0000 (22:41 +0100)
commitc4475c0a577308c81f4cddfc48b34b4d14fadf02
tree720af466d7d609f860a24f9347482e480dae856d
parentac58fc650c49d52539a221f1f31d6f2e19d00203
package/sqlite: security bump to version 3.25.3

Fixes CVE-2018-20346: SQLite before 3.25.3, when the FTS3 extension is
enabled, encounters an integer overflow (and resultant buffer overflow) for
FTS3 queries that occur after crafted changes to FTS3 shadow tables,
allowing remote attackers to execute arbitrary code by leveraging the
ability to run arbitrary SQL statements (such as in certain WebSQL use
cases), aka Magellan.

For more details, see:
https://blade.tencent.com/magellan/index_en.html
https://www.sqlite.org/releaselog/3_25_3.html
https://www.mail-archive.com/sqlite-users@mailinglists.sqlite.org/msg113218.html

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
package/sqlite/sqlite.hash
package/sqlite/sqlite.mk