sqlite3-ruby
This module allows Ruby programs to interface with the SQLite3 database engine (http://www.sqlite.org). You must have the SQLite engine installed in order to build this module. Note that this module is NOT compatible with SQLite 2.x.
Activity
- Latest release
- 15y ago
- Total releases
- 19
- Cadence
- ~26 days
- Last 12 months
- 0
Details
- First release
- Dec 21, 2004
| Version | Released | |
|---|---|---|
1.3.3
patch
1 CVE
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.5.0
0.6.0
0.9.0
1.0.0
1.0.1
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
+ 7 more Show less
1.3.0
1.3.0.beta.1
1.3.0.beta.2
1.3.1
1.3.2
1.3.3
1.3.3.beta.1
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
1.3.3.beta.1
pre
1 CVE
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.5.0
0.6.0
0.9.0
1.0.0
1.0.1
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
+ 7 more Show less
1.3.0
1.3.0.beta.1
1.3.0.beta.2
1.3.1
1.3.2
1.3.3
1.3.3.beta.1
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
1.3.2
patch
1 CVE
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.5.0
0.6.0
0.9.0
1.0.0
1.0.1
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
+ 7 more Show less
1.3.0
1.3.0.beta.1
1.3.0.beta.2
1.3.1
1.3.2
1.3.3
1.3.3.beta.1
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
1.3.1
patch
1 CVE
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.5.0
0.6.0
0.9.0
1.0.0
1.0.1
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
+ 7 more Show less
1.3.0
1.3.0.beta.1
1.3.0.beta.2
1.3.1
1.3.2
1.3.3
1.3.3.beta.1
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
1.3.0
minor
1 CVE
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.5.0
0.6.0
0.9.0
1.0.0
1.0.1
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
+ 7 more Show less
1.3.0
1.3.0.beta.1
1.3.0.beta.2
1.3.1
1.3.2
1.3.3
1.3.3.beta.1
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
1.3.0.beta.2
pre
1 CVE
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.5.0
0.6.0
0.9.0
1.0.0
1.0.1
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
+ 7 more Show less
1.3.0
1.3.0.beta.1
1.3.0.beta.2
1.3.1
1.3.2
1.3.3
1.3.3.beta.1
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
1.3.0.beta.1
pre
1 CVE
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.5.0
0.6.0
0.9.0
1.0.0
1.0.1
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
+ 7 more Show less
1.3.0
1.3.0.beta.1
1.3.0.beta.2
1.3.1
1.3.2
1.3.3
1.3.3.beta.1
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
1.2.5
patch
1 CVE
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.5.0
0.6.0
0.9.0
1.0.0
1.0.1
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
+ 7 more Show less
1.3.0
1.3.0.beta.1
1.3.0.beta.2
1.3.1
1.3.2
1.3.3
1.3.3.beta.1
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
1.2.4
patch
1 CVE
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.5.0
0.6.0
0.9.0
1.0.0
1.0.1
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
+ 7 more Show less
1.3.0
1.3.0.beta.1
1.3.0.beta.2
1.3.1
1.3.2
1.3.3
1.3.3.beta.1
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
1.2.3
patch
2 CVEs
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.5.0
0.6.0
0.9.0
1.0.0
1.0.1
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
+ 7 more Show less
1.3.0
1.3.0.beta.1
1.3.0.beta.2
1.3.1
1.3.2
1.3.3
1.3.3.beta.1
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev
CVE-2011-0995
GHSA-6x46-7rrv-m4h8
Oct 24, 2017
sqlite3-ruby uses weak permissions for unspecified files, which allows local users to gain privileges
Low
The sqlite3-ruby gem in the rubygem-sqlite3 package before 1.2.4-0.5.1 in SUSE Linux Enterprise (SLE) 11 SP1 uses weak permissions for unspecified files, which allows local users to gain privileges via unknown vectors. Affected versions
0.5.0
0.6.0
0.9.0
1.0.0
1.0.1
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
Fixed in
1.2.4
References
Updated Nov 29, 2024 · Source: OSV.dev | ||
1.2.2
patch
2 CVEs
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.5.0
0.6.0
0.9.0
1.0.0
1.0.1
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
+ 7 more Show less
1.3.0
1.3.0.beta.1
1.3.0.beta.2
1.3.1
1.3.2
1.3.3
1.3.3.beta.1
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev
CVE-2011-0995
GHSA-6x46-7rrv-m4h8
Oct 24, 2017
sqlite3-ruby uses weak permissions for unspecified files, which allows local users to gain privileges
Low
The sqlite3-ruby gem in the rubygem-sqlite3 package before 1.2.4-0.5.1 in SUSE Linux Enterprise (SLE) 11 SP1 uses weak permissions for unspecified files, which allows local users to gain privileges via unknown vectors. Affected versions
0.5.0
0.6.0
0.9.0
1.0.0
1.0.1
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
Fixed in
1.2.4
References
Updated Nov 29, 2024 · Source: OSV.dev | ||
1.2.1
patch
2 CVEs
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.5.0
0.6.0
0.9.0
1.0.0
1.0.1
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
+ 7 more Show less
1.3.0
1.3.0.beta.1
1.3.0.beta.2
1.3.1
1.3.2
1.3.3
1.3.3.beta.1
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev
CVE-2011-0995
GHSA-6x46-7rrv-m4h8
Oct 24, 2017
sqlite3-ruby uses weak permissions for unspecified files, which allows local users to gain privileges
Low
The sqlite3-ruby gem in the rubygem-sqlite3 package before 1.2.4-0.5.1 in SUSE Linux Enterprise (SLE) 11 SP1 uses weak permissions for unspecified files, which allows local users to gain privileges via unknown vectors. Affected versions
0.5.0
0.6.0
0.9.0
1.0.0
1.0.1
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
Fixed in
1.2.4
References
Updated Nov 29, 2024 · Source: OSV.dev | ||
1.2.0
minor
2 CVEs
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.5.0
0.6.0
0.9.0
1.0.0
1.0.1
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
+ 7 more Show less
1.3.0
1.3.0.beta.1
1.3.0.beta.2
1.3.1
1.3.2
1.3.3
1.3.3.beta.1
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev
CVE-2011-0995
GHSA-6x46-7rrv-m4h8
Oct 24, 2017
sqlite3-ruby uses weak permissions for unspecified files, which allows local users to gain privileges
Low
The sqlite3-ruby gem in the rubygem-sqlite3 package before 1.2.4-0.5.1 in SUSE Linux Enterprise (SLE) 11 SP1 uses weak permissions for unspecified files, which allows local users to gain privileges via unknown vectors. Affected versions
0.5.0
0.6.0
0.9.0
1.0.0
1.0.1
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
Fixed in
1.2.4
References
Updated Nov 29, 2024 · Source: OSV.dev | ||
1.1.0
minor
2 CVEs
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.5.0
0.6.0
0.9.0
1.0.0
1.0.1
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
+ 7 more Show less
1.3.0
1.3.0.beta.1
1.3.0.beta.2
1.3.1
1.3.2
1.3.3
1.3.3.beta.1
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev
CVE-2011-0995
GHSA-6x46-7rrv-m4h8
Oct 24, 2017
sqlite3-ruby uses weak permissions for unspecified files, which allows local users to gain privileges
Low
The sqlite3-ruby gem in the rubygem-sqlite3 package before 1.2.4-0.5.1 in SUSE Linux Enterprise (SLE) 11 SP1 uses weak permissions for unspecified files, which allows local users to gain privileges via unknown vectors. Affected versions
0.5.0
0.6.0
0.9.0
1.0.0
1.0.1
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
Fixed in
1.2.4
References
Updated Nov 29, 2024 · Source: OSV.dev | ||
1.0.1
patch
2 CVEs
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.5.0
0.6.0
0.9.0
1.0.0
1.0.1
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
+ 7 more Show less
1.3.0
1.3.0.beta.1
1.3.0.beta.2
1.3.1
1.3.2
1.3.3
1.3.3.beta.1
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev
CVE-2011-0995
GHSA-6x46-7rrv-m4h8
Oct 24, 2017
sqlite3-ruby uses weak permissions for unspecified files, which allows local users to gain privileges
Low
The sqlite3-ruby gem in the rubygem-sqlite3 package before 1.2.4-0.5.1 in SUSE Linux Enterprise (SLE) 11 SP1 uses weak permissions for unspecified files, which allows local users to gain privileges via unknown vectors. Affected versions
0.5.0
0.6.0
0.9.0
1.0.0
1.0.1
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
Fixed in
1.2.4
References
Updated Nov 29, 2024 · Source: OSV.dev | ||
1.0.0
major
2 CVEs
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.5.0
0.6.0
0.9.0
1.0.0
1.0.1
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
+ 7 more Show less
1.3.0
1.3.0.beta.1
1.3.0.beta.2
1.3.1
1.3.2
1.3.3
1.3.3.beta.1
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev
CVE-2011-0995
GHSA-6x46-7rrv-m4h8
Oct 24, 2017
sqlite3-ruby uses weak permissions for unspecified files, which allows local users to gain privileges
Low
The sqlite3-ruby gem in the rubygem-sqlite3 package before 1.2.4-0.5.1 in SUSE Linux Enterprise (SLE) 11 SP1 uses weak permissions for unspecified files, which allows local users to gain privileges via unknown vectors. Affected versions
0.5.0
0.6.0
0.9.0
1.0.0
1.0.1
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
Fixed in
1.2.4
References
Updated Nov 29, 2024 · Source: OSV.dev | ||
0.9.0
minor
2 CVEs
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.5.0
0.6.0
0.9.0
1.0.0
1.0.1
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
+ 7 more Show less
1.3.0
1.3.0.beta.1
1.3.0.beta.2
1.3.1
1.3.2
1.3.3
1.3.3.beta.1
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev
CVE-2011-0995
GHSA-6x46-7rrv-m4h8
Oct 24, 2017
sqlite3-ruby uses weak permissions for unspecified files, which allows local users to gain privileges
Low
The sqlite3-ruby gem in the rubygem-sqlite3 package before 1.2.4-0.5.1 in SUSE Linux Enterprise (SLE) 11 SP1 uses weak permissions for unspecified files, which allows local users to gain privileges via unknown vectors. Affected versions
0.5.0
0.6.0
0.9.0
1.0.0
1.0.1
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
Fixed in
1.2.4
References
Updated Nov 29, 2024 · Source: OSV.dev | ||
0.6.0
minor
2 CVEs
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.5.0
0.6.0
0.9.0
1.0.0
1.0.1
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
+ 7 more Show less
1.3.0
1.3.0.beta.1
1.3.0.beta.2
1.3.1
1.3.2
1.3.3
1.3.3.beta.1
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev
CVE-2011-0995
GHSA-6x46-7rrv-m4h8
Oct 24, 2017
sqlite3-ruby uses weak permissions for unspecified files, which allows local users to gain privileges
Low
The sqlite3-ruby gem in the rubygem-sqlite3 package before 1.2.4-0.5.1 in SUSE Linux Enterprise (SLE) 11 SP1 uses weak permissions for unspecified files, which allows local users to gain privileges via unknown vectors. Affected versions
0.5.0
0.6.0
0.9.0
1.0.0
1.0.1
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
Fixed in
1.2.4
References
Updated Nov 29, 2024 · Source: OSV.dev | ||
0.5.0
initial
2 CVEs
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.5.0
0.6.0
0.9.0
1.0.0
1.0.1
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
+ 7 more Show less
1.3.0
1.3.0.beta.1
1.3.0.beta.2
1.3.1
1.3.2
1.3.3
1.3.3.beta.1
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev
CVE-2011-0995
GHSA-6x46-7rrv-m4h8
Oct 24, 2017
sqlite3-ruby uses weak permissions for unspecified files, which allows local users to gain privileges
Low
The sqlite3-ruby gem in the rubygem-sqlite3 package before 1.2.4-0.5.1 in SUSE Linux Enterprise (SLE) 11 SP1 uses weak permissions for unspecified files, which allows local users to gain privileges via unknown vectors. Affected versions
0.5.0
0.6.0
0.9.0
1.0.0
1.0.1
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
Fixed in
1.2.4
References
Updated Nov 29, 2024 · Source: OSV.dev |