Hi Laszlo, On Mon, Jun 10, 2019 at 05:06:07PM +0000, Debian Bug Tracking System wrote: > sqlite3 (3.27.2-3) unstable; urgency=high > . > * Backport security related patches: [...] > - prevent aliases of window functions expressions from being used as > arguments to aggregate or other window functions (probably fixing > CVE-2019-5018) (closes: #928770),
Did you got any upstream confirmation or from TALOS project that this one was the right fixes to pick for the CVE-2019-5018 issue? Regards, Salvatore