1"use strict";(self.webpackChunkelectronjs=self.webpackChunkelectronjs||[]).push([["35375"],{681(e,t,r){r.r(t),r.d(t,{assets:()=>s,contentTitle:()=>o,default:()=>u,frontMatter:()=>a,metadata:()=>n,toc:()=>c});var n=r(40685),i=r(74848),l=r(28453);let a={title:"SQLite Vulnerability Fix",date:new Date("2018-12-18T00:00:00.000Z"),authors:"ckerr",slug:"magellan-fix",tags:["security"]},o,s={authorsImageUrls:[void 0]},c=[{value:"Scope",id:"scope",level:2},{value:"Mitigation",id:"mitigation",level:2},{value:"Further Information",id:"further-information",level:2}];function h(e){let t={a:"a",h2:"h2",hr:"hr",li:"li",p:"p",ul:"ul",...(0,l.R)(),...e.components};return(0,i.jsxs)(i.Fragment,{children:[(0,i.jsxs)(t.p,{children:['A remote code execution vulnerability, "',(0,i.jsx)(t.a,{href:"https://blade.tencent.com/magellan/index_en.html",children:"Magellan"}),'," has been discovered affecting software based on SQLite or Chromium, including all versions of Electron.']}),"\n",(0,i.jsx)(t.hr,{}),"\n",(0,i.jsx)(t.h2,{id:"scope",children:"Scope"}),"\n",(0,i.jsx)(t.p,{children:"Electron applications using Web SQL are impacted."}),"\n",(0,i.jsx)(t.h2,{id:"mitigation",children:"Mitigation"}),"\n",(0,i.jsx)(t.p,{children:"Affected apps should stop using Web SQL or upgrade to a patched version of Electron."}),"\n",(0,i.jsx)(t.p,{children:"We've published new versions of Electron which include fixes for this vulnerability:"}),"\n",(0,i.jsxs)(t.ul,{children:["\n",(0,i.jsx)(t.li,{children:(0,i.jsx)(t.a,{href:"https://github.com/electron/electron/releases/tag/v4.0.0-beta.11",children:"4.0.0-beta.11"})}),"\n",(0,i.jsx)(t.li,{children:(0,i.jsx)(t.a,{href:"https://github.com/electron/electron/releases/tag/v3.1.0-beta.4",children:"3.1.0-beta.4"})}),"\n",(0,i.jsx)(t.li,{children:(0,i.jsx)(t.a,{href:"https://github.com/electron/electron/releases/tag/v3.0.13",children:"3.0.13"})}),"\n",(0,i.jsx)(t.li,{children:(0,i.jsx)(t.a,{href:"https://github.com/electron/electron/releases/tag/v2.0.16",children:"2.0.16"})}),"\n"]}),"\n",(0,i.jsx)(t.p,{children:"There are no reports of this in the wild; however, affected applications are urged to mitigate."}),"\n",(0,i.jsx)(t.h2,{id:"further-information",children:"Further Information"}),"\n",(0,i.jsxs)(t.p,{children:["This vulnerability was discovered by the Tencent Blade team, who have published ",(0,i.jsx)(t.a,{href:"https://blade.tencent.com/magellan/index_en.html",children:"a blog post that discusses the vulnerability"}),"."]}),"\n",(0,i.jsxs)(t.p,{children:["To learn more about best practices for keeping your Electron apps secure, see our ",(0,i.jsx)(t.a,{href:"https://electronjs.org/docs/tutorial/security",children:"security tutorial"}),"."]}),"\n",(0,i.jsxs)(t.p,{children:["Please file a ",(0,i.jsx)(t.a,{href:"https://github.com/electron/electron/security",children:"GitHub Security Advisory"})," if you wish to report a vulnerability\nin Electron."]})]})}function u(e={}){let{wrapper:t}={...(0,l.R)(),...e.components};return t?(0,i.jsx)(t,{...e,children:(0,i.jsx)(h,{...e})}):h(e)}},28453(e,t,r){r.d(t,{R:()=>a,x:()=>o});var n=r(96540);let i={},l=n.createContext(i);function a(e){let t=n.useContext(l);return n.useMemo(function(){return"function"==typeof e?e(t):{...t,...e}},[t,e])}function o(e){let t;return t=e.disableParentContext?"function"==typeof e.components?e.components(i):e.components||i:a(e.components),n.createElement(l.Provider,{value:t},e.children)}},40685(e){e.exports=JSON.parse('{"permalink":"/blog/magellan-fix","source":"@site/blog/magellan-fix.md","title":"SQLite Vulnerability Fix","description":"A remote code execution vulnerability, \\"Magellan,\\" has been discovered affecting software based on SQLite or Chromium, including all versions of Electron.","date":"2018-12-18T00:00:00.000Z","tags":[{"inline":false,"label":"Security","permalink":"/blog/tags/security","description":"Blog posts related to security"}],"readingTime":0.94,"hasTruncateMarker":false,"authors":[{"name":"ckerr","url":"https://github.com/ckerr","imageURL":"https://github.com/ckerr.png?size=96","key":"ckerr","page":null}],"frontMatter":{"title":"SQLite Vulnerability Fix","date":"2018-12-18T00:00:00.000Z","authors":"ckerr","slug":"magellan-fix","tags":["security"]},"unlisted":false,"prevItem":{"title":"Electron 4.0.0","permalink":"/blog/electron-4-0"},"nextItem":{"title":"Electron App Feedback Program","permalink":"/blog/app-feedback-program"}}')}
1}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.