Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-19959

Опубликовано: 03 янв. 2020
Источник: debian

Описание

ext/misc/zipfile.c in SQLite 3.30.1 mishandles certain uses of INSERT INTO in situations involving embedded '\0' characters in filenames, leading to a memory-management error that can be detected by (for example) valgrind.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
sqlite3fixed3.30.1+fossil191229-1package
sqlite3fixed3.27.2-3+deb10u1busterpackage
sqlite3not-affectedstretchpackage
sqlite3not-affectedjessiepackage
sqlitenot-affectedpackage

Примечания

  • https://github.com/sqlite/sqlite/commit/1e490c4ca6b43a9cf8637d695907888349f69bec

  • https://github.com/sqlite/sqlite/commit/d8f2d46cbc9925e034a68aaaf60aad788d9373c1

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 6 лет назад

ext/misc/zipfile.c in SQLite 3.30.1 mishandles certain uses of INSERT INTO in situations involving embedded '\0' characters in filenames, leading to a memory-management error that can be detected by (for example) valgrind.

CVSS3: 7.3
redhat
около 6 лет назад

ext/misc/zipfile.c in SQLite 3.30.1 mishandles certain uses of INSERT INTO in situations involving embedded '\0' characters in filenames, leading to a memory-management error that can be detected by (for example) valgrind.

CVSS3: 7.5
nvd
около 6 лет назад

ext/misc/zipfile.c in SQLite 3.30.1 mishandles certain uses of INSERT INTO in situations involving embedded '\0' characters in filenames, leading to a memory-management error that can be detected by (for example) valgrind.

github
больше 3 лет назад

ext/misc/zipfile.c in SQLite 3.30.1 mishandles certain uses of INSERT INTO in situations involving embedded '\0' characters in filenames, leading to a memory-management error that can be detected by (for example) valgrind.

CVSS3: 7.5
fstec
около 6 лет назад

Уязвимость функции zipfile() системы управления базами данных SQLite, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код