Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f92h-rw3f-8j92

Опубликовано: 29 дек. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionReadRecord of the file ext/session/sqlite3session.c of the component make alltest Handler. The manipulation leads to heap-based buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-248999.

A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionReadRecord of the file ext/session/sqlite3session.c of the component make alltest Handler. The manipulation leads to heap-based buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-248999.

EPSS

Процентиль: 30%
0.00109
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-119
CWE-122

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 1 года назад

A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionReadRecord of the file ext/session/sqlite3session.c of the component make alltest Handler. The manipulation leads to heap-based buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-248999.

CVSS3: 7.3
redhat
больше 1 года назад

A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionReadRecord of the file ext/session/sqlite3session.c of the component make alltest Handler. The manipulation leads to heap-based buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-248999.

CVSS3: 5.5
nvd
больше 1 года назад

A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionReadRecord of the file ext/session/sqlite3session.c of the component make alltest Handler. The manipulation leads to heap-based buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-248999.

CVSS3: 7.3
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 5.5
debian
больше 1 года назад

A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classifie ...

EPSS

Процентиль: 30%
0.00109
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-119
CWE-122