Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-19880

Опубликовано: 18 дек. 2019
Источник: debian

Описание

exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values in ORDER BY clauses of window definitions are mishandled.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
sqlite3fixed3.30.1+fossil191229-1package
sqlite3not-affectedbusterpackage
sqlite3not-affectedstretchpackage
sqlite3not-affectedjessiepackage
sqlitenot-affectedpackage
chromiumfixed80.0.3987.106-1package
chromiumend-of-lifestretchpackage

Примечания

  • Introduced in: https://github.com/sqlite/sqlite/commit/08f6de7f314ad6b15d34cc5f27c3e737fcd99268 (3.29.0)

  • Fixed by: https://github.com/sqlite/sqlite/commit/75e95e1fcd52d3ec8282edb75ac8cd0814095d54

  • When fixing this issue make sure to apply as well

  • https://github.com/sqlite/sqlite/commit/8428b3b437569338a9d1e10c4cd8154acbe33089

  • to not open CVE-2019-19926.

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 6 лет назад

exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values in ORDER BY clauses of window definitions are mishandled.

CVSS3: 7.5
redhat
около 6 лет назад

exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values in ORDER BY clauses of window definitions are mishandled.

CVSS3: 7.5
nvd
около 6 лет назад

exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values in ORDER BY clauses of window definitions are mishandled.

CVSS3: 7.5
github
больше 3 лет назад

exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values in ORDER BY clauses of window definitions are mishandled.

CVSS3: 7.5
fstec
около 6 лет назад

Уязвимость функции exprListAppendList () системы управления базами данных SQLite, позволяющая нарушителю вызвать отказ в обслуживании