Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h2g7-95mc-8g48

Опубликовано: 29 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 9.1

Описание

An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of service or disclose sensitive information from process memory via a crafted SELECT statement with a large number of expressions in the ORDER BY clause.

An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of service or disclose sensitive information from process memory via a crafted SELECT statement with a large number of expressions in the ORDER BY clause.

EPSS

Процентиль: 12%
0.0022
Низкий

6.9 Medium

CVSS4

9.1 Critical

CVSS3

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 9.1
ubuntu
11 месяцев назад

An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of service or disclose sensitive information from process memory via a crafted SELECT statement with a large number of expressions in the ORDER BY clause.

CVSS3: 6.1
redhat
11 месяцев назад

An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of service or disclose sensitive information from process memory via a crafted SELECT statement with a large number of expressions in the ORDER BY clause.

CVSS3: 9.1
nvd
11 месяцев назад

An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of service or disclose sensitive information from process memory via a crafted SELECT statement with a large number of expressions in the ORDER BY clause.

CVSS3: 9.1
msrc
10 месяцев назад

SQLite integer overflow in key info allocation may lead to information disclosure.

CVSS3: 9.1
debian
11 месяцев назад

An integer overflow in the sqlite3KeyInfoFromExprList function in SQLi ...

EPSS

Процентиль: 12%
0.0022
Низкий

6.9 Medium

CVSS4

9.1 Critical

CVSS3

Дефекты

CWE-190