Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-70873

Опубликовано: 12 мар. 2026
Источник: debian
EPSS Низкий

Описание

An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
sqlite3unfixedpackage

Примечания

  • https://sqlite.org/src/info/3d459f1fb1bd1b5e

  • https://sqlite.org/forum/forumpost/761eac3c82

  • https://gist.github.com/cnwangjihe/f496393f30f5ecec5b18c8f5ab072054

  • zipfile extension not build for Debian binary package builds

EPSS

Процентиль: 22%
0.00301
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
5 месяцев назад

An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.

CVSS3: 3.3
redhat
5 месяцев назад

An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.

CVSS3: 7.5
nvd
5 месяцев назад

An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.

CVSS3: 7.5
msrc
4 месяца назад

An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.

CVSS3: 7.5
github
5 месяцев назад

An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.

EPSS

Процентиль: 22%
0.00301
Низкий