go-gorm / sqlite

GORM sqlite driver
MIT License
169 stars 174 forks source link

Heap-based Buffer Overflow reported in dependency mattn/go-sqlite3 package #176

Open robert-t7k opened 8 months ago

robert-t7k commented 8 months ago

Description

CVE-2023-7104 has been reported for github.com/mattn/go-sqlite3 package, versions <1.14.18 as reported by Snyk https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMMATTNGOSQLITE3-6139875

This dependency update has an already existing PR created by dependabot https://github.com/go-gorm/sqlite/pull/175