{"id":8066,"date":"2018-12-18T00:57:00","date_gmt":"2018-12-17T23:57:00","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=8066"},"modified":"2020-02-03T23:35:53","modified_gmt":"2020-02-03T22:35:53","slug":"magellan-sqlite-vulnerability-puts-million-apps-at-risk","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2018\/12\/18\/magellan-sqlite-vulnerability-puts-million-apps-at-risk\/","title":{"rendered":"Magellan: SQLite vulnerability puts Million Apps at Risk"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2015\/01\/Schutz.jpg\" width=\"40\" align=\"left\" height=\"47\">[<a href=\"https:\/\/www.borncity.com\/blog\/2018\/12\/16\/magellan-sqlite-schwachstelle-gefhrdet-viele-apps\/\" target=\"_blank\" rel=\"noopener noreferrer\">German<\/a>]Security researchers have discovered a critical vulnerability (Magellan) in the widely used SQLite database software. This could allow attackers to remotely execute arbitrary or malicious code on affected devices.<\/p>\n<p><!--more--><\/p>\n<h2>What's SQLite?<\/h2>\n<p><a href=\"https:\/\/en.wikipedia.org\/wiki\/SQLite\" target=\"_blank\" rel=\"noopener noreferrer\">SQLite<\/a> is a widely used relational database management system that has minimal requirements from operating systems or external libraries. Therefore it is compatible with almost all devices, platforms and programming languages and is widely used for data storage in app and application development.<\/p>\n<h2>The SQLite vulnerability<\/h2>\n<p>The Hacker News <a href=\"https:\/\/thehackernews.com\/2018\/12\/sqlite-vulnerability.html\" target=\"_blank\" rel=\"noopener noreferrer\">reported here<\/a> that Tencent's Blade security team has <a href=\"https:\/\/web.archive.org\/web\/20191007231454\/https:\/\/blade.tencent.com\/magellan\/index_en.html\" target=\"_blank\" rel=\"noopener noreferrer\">discovered a vulnerability<\/a>, named Magellan, in SQLite. This vulnerability in in older SQLite versions could allow attackers to execute arbitrary code on affected devices over the Internet or a network.&nbsp; <\/p>\n<p>The problem is that SQL is not only used by millions of apps and applications, but also by browsers based on Chromium. So anyone using an SQL dependant app, application or Chromium-based browser may be vulnerable. <\/p>\n<p>So far, however, the discoverers of the vulnerability have not been aware of any cases in which it has been exploited. For security reasons, security specialists do not disclose details of the vulnerability.<\/p>\n<h2>When will the vulnerability be fixed?<\/h2>\n<p>SQLite has released <a href=\"https:\/\/www.sqlite.org\/releaselog\/3_26_0.html\" target=\"_blank\" rel=\"noopener noreferrer\">version 3.26.0<\/a>, which&nbsp; fixes the bug. Users can only rely on developers who use SQLite in their apps and applications to create and deliver an update of the SQLite libraries used to this version. <\/p>\n<p>For the Google Chrome browser and all other browsers based on Chromium, the SQLite vulnerability should be fixed with Chromium version 71.0.3578.80 (<a href=\"https:\/\/chromereleases.googleblog.com\/2018\/12\/stable-channel-update-for-desktop.html\" target=\"_blank\" rel=\"noopener noreferrer\">released<\/a> December 4, 2018). <\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]Security researchers have discovered a critical vulnerability (Magellan) in the widely used SQLite database software. This could allow attackers to remotely execute arbitrary or malicious code on affected devices.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[580],"tags":[69],"class_list":["post-8066","post","type-post","status-publish","format-standard","hentry","category-security","tag-security"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/8066","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=8066"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/8066\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=8066"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=8066"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=8066"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}