https://vuxml.freebsd.org/freebsd/f51077bd-6dd7-11f0-9d62-b42e991fc52e.html says that sqlite3 after 3.39.2 and before 3.41.1 is vulnerable,
but "pkg audit" flags the current version (3.50.2_1,1) as at risk.
Is that a problem in the audit tests or the vulnerabililty description?
(Somewhat unusually, the "Affected packages" description has 2 lines:
"3.39.2 < sqlite3" and "sqlite3 < 3.41.1" rather than 1 line
"3.39.2 < sqlite3 < 3.41.1", suggesting 2 audit rules instead of 1,
the first of which (by itself) would match 3.50.)
Sysop: | Keyop |
---|---|
Location: | Huddersfield, West Yorkshire, UK |
Users: | 546 |
Nodes: | 16 (2 / 14) |
Uptime: | 47:22:21 |
Calls: | 10,397 |
Calls today: | 5 |
Files: | 14,066 |
Messages: | 6,417,282 |
Posted today: | 1 |