Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-5018

Опубликовано: 10 мая 2019
Источник: debian
EPSS Низкий

Описание

An exploitable use after free vulnerability exists in the window function functionality of Sqlite3 3.26.0. A specially crafted SQL command can cause a use after free vulnerability, potentially resulting in remote code execution. An attacker can send a malicious SQL command to trigger this vulnerability.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
sqlite3fixed3.27.2-3package
sqlite3not-affectedstretchpackage
sqlite3not-affectedjessiepackage
sqlitenot-affectedpackage

Примечания

  • https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0777

EPSS

Процентиль: 91%
0.07405
Низкий

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 6 лет назад

An exploitable use after free vulnerability exists in the window function functionality of Sqlite3 3.26.0. A specially crafted SQL command can cause a use after free vulnerability, potentially resulting in remote code execution. An attacker can send a malicious SQL command to trigger this vulnerability.

CVSS3: 8.1
redhat
больше 6 лет назад

An exploitable use after free vulnerability exists in the window function functionality of Sqlite3 3.26.0. A specially crafted SQL command can cause a use after free vulnerability, potentially resulting in remote code execution. An attacker can send a malicious SQL command to trigger this vulnerability.

CVSS3: 8.1
nvd
больше 6 лет назад

An exploitable use after free vulnerability exists in the window function functionality of Sqlite3 3.26.0. A specially crafted SQL command can cause a use after free vulnerability, potentially resulting in remote code execution. An attacker can send a malicious SQL command to trigger this vulnerability.

CVSS3: 8.1
github
больше 3 лет назад

An exploitable use after free vulnerability exists in the window function functionality of Sqlite3 3.26.0. A specially crafted SQL command can cause a use after free vulnerability, potentially resulting in remote code execution. An attacker can send a malicious SQL command to trigger this vulnerability.

CVSS3: 8.1
fstec
почти 6 лет назад

Уязвимость системы управления базами данных SQLite, связанная с использованием памяти после освобождения, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 91%
0.07405
Низкий