• Sources: primary, discussion
  • Summary: The writeup shows that the sqlite_dbpage virtual table lets arbitrary SQL write a shared object to disk and reach code execution without loading a SQLite extension. The author calls sqlite_dbpage a built-in extension often enabled by default, demonstrates it on Python and Ruby, and reports the technique fails on standard Node.js images because the mainstream SQLite libraries there do not enable it. The exploit also needs the process to crash so the shared object is reloaded, and the post does not name affected SQLite versions.
  • Why it matters: Where the table is enabled, disabling extension loading is not the boundary it was assumed to be, because arbitrary SQL reaches code execution without it.

send feedback on this story