adịghị ike na SQLite DBMS

Na SQLite DBMS mara adịghị ike (CVE-2019-5018), nke na-enye gị ohere ime koodu gị na sistemụ ma ọ bụrụ na ọ ga-ekwe omume ịme ajụjụ SQL nke onye mwakpo kwadebere. A na-akpata nsogbu ahụ site na njehie na mmejuputa ọrụ windo na-egosi na-amalite site na alaka ụlọ ọrụ SQLite 3.26. adịghị ike kpochapuru na mbipụta Eprel SQLite 3.28 na-enweghị nkọwa doro anya maka idozi nsogbu nchekwa.

Ajụjụ SQL SELECT emepụtara nke ọma nwere ike ibute ohere ebe nchekwa na-enweghị ya, nke enwere ike iji mepụta nrigbu iji mebie koodu n'ọnọdụ nke ngwa site na iji SQLite. Enwere ike iji adịghị ike ahụ eme ihe ma ọ bụrụ na ngwa ahụ na-enye ohere ka ihe nrụpụta SQL na-abịa site na mpụga gafere na SQLite.

Dịka ọmụmaatụ, enwere ike ịme mwakpo na ihe nchọgharị Chrome na ngwa site na iji injin Chromium, ebe ọ bụ na emejuputa WebSQL API n'elu SQLite wee nweta DBMS a iji hazie ajụjụ SQL site na ngwa webụ. Iji wakpo, o zuru ezu imepụta ibe nwere koodu Javascript ọjọọ wee manye onye ọrụ imepe ya na ihe nchọgharị dabere na injin Chromium.

isi: opennet.ru

Tinye a comment