Skip to content

Commit 132860c

Browse files
jasnowRubySec CI
authored and
RubySec CI
committed
Updated advisory posts against rubysec/ruby-advisory-db@b3d2f38
1 parent 95c69be commit 132860c

File tree

1 file changed

+29
-0
lines changed

1 file changed

+29
-0
lines changed
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,29 @@
1+
---
2+
layout: advisory
3+
title: 'CVE-2024-46488 (sqlite-vec): Heap-based Buffer Overflow in sqlite-vec'
4+
comments: false
5+
categories:
6+
- sqlite-vec
7+
advisory:
8+
gem: sqlite-vec
9+
cve: 2024-46488
10+
ghsa: vrcx-gx3g-j3h8
11+
url: https://github.com/advisories/GHSA-vrcx-gx3g-j3h8
12+
title: Heap-based Buffer Overflow in sqlite-vec
13+
date: 2024-09-25
14+
description: |
15+
sqlite-vec v0.1.1 was discovered to contain a heap buffer overflow
16+
via the npy_token_next function. This vulnerability allows attackers
17+
to cause a Denial of Service (DoS) via a crafted file.
18+
19+
Workaround for CVE in release 0.1.3.
20+
cvss_v3: 9.1
21+
patched_versions:
22+
- ">= 0.1.3"
23+
related:
24+
url:
25+
- https://nvd.nist.gov/vuln/detail/CVE-2024-46488
26+
- https://github.com/asg017/sqlite-vec/releases/tag/v0.1.3
27+
- https://github.com/VulnSphere/LLMVulnSphere/blob/main/VectorDB/sqlite-vec/OOBR_2.md
28+
- https://github.com/advisories/GHSA-vrcx-gx3g-j3h8
29+
---

0 commit comments

Comments
 (0)