Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-16168

Опубликовано: 09 сент. 2019
Источник: debian
EPSS Низкий

Описание

In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validation of a sqlite_stat1 sz field, aka a "severe division by zero in the query planner."

Пакеты

ПакетСтатусВерсия исправленияРелизТип
sqlite3fixed3.29.0-2package
sqlite3fixed3.27.2-3+deb10u1busterpackage
sqlite3no-dsajessiepackage
sqlitenot-affectedpackage

Примечания

  • https://www.mail-archive.com/sqlite-users@mailinglists.sqlite.org/msg116312.html

  • https://www.sqlite.org/src/info/e4598ecbdd18bd82945f6029013296690e719a62

  • Fixed by: https://www.sqlite.org/src/info/98357d8c1263920b (v3.30.0)

  • Introduced by: https://www.sqlite.org/src/info/90e36676476e8db0 (v3.8.5)

  • https://github.com/sqlite/sqlite/commit/725dd72400872da94dcfb6af48128905b93d57fe

EPSS

Процентиль: 74%
0.00863
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 6 лет назад

In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validation of a sqlite_stat1 sz field, aka a "severe division by zero in the query planner."

CVSS3: 6.5
redhat
около 6 лет назад

In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validation of a sqlite_stat1 sz field, aka a "severe division by zero in the query planner."

CVSS3: 6.5
nvd
около 6 лет назад

In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validation of a sqlite_stat1 sz field, aka a "severe division by zero in the query planner."

CVSS3: 6.5
msrc
около 1 года назад

Описание отсутствует

suse-cvrf
почти 6 лет назад

Security update for sqlite3

EPSS

Процентиль: 74%
0.00863
Низкий