Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r659-6fh2-v3gv

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Zetetic SQLCipher 4.x before 4.4.3 has a NULL pointer dereferencing issue related to sqlcipher_export in crypto.c and sqlite3StrICmp in sqlite3.c. This may allow an attacker to perform a remote denial of service attack. For example, an SQL injection can be used to execute the crafted SQL command sequence, which causes a segmentation fault.

Zetetic SQLCipher 4.x before 4.4.3 has a NULL pointer dereferencing issue related to sqlcipher_export in crypto.c and sqlite3StrICmp in sqlite3.c. This may allow an attacker to perform a remote denial of service attack. For example, an SQL injection can be used to execute the crafted SQL command sequence, which causes a segmentation fault.

EPSS

Процентиль: 69%
0.00603
Низкий

7.5 High

CVSS3

Дефекты

CWE-476
CWE-89

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 5 лет назад

Zetetic SQLCipher 4.x before 4.4.3 has a NULL pointer dereferencing issue related to sqlcipher_export in crypto.c and sqlite3StrICmp in sqlite3.c. This may allow an attacker to perform a remote denial of service attack. For example, an SQL injection can be used to execute the crafted SQL command sequence, which causes a segmentation fault.

CVSS3: 7.5
nvd
почти 5 лет назад

Zetetic SQLCipher 4.x before 4.4.3 has a NULL pointer dereferencing issue related to sqlcipher_export in crypto.c and sqlite3StrICmp in sqlite3.c. This may allow an attacker to perform a remote denial of service attack. For example, an SQL injection can be used to execute the crafted SQL command sequence, which causes a segmentation fault.

CVSS3: 7.5
debian
почти 5 лет назад

Zetetic SQLCipher 4.x before 4.4.3 has a NULL pointer dereferencing is ...

EPSS

Процентиль: 69%
0.00603
Низкий

7.5 High

CVSS3

Дефекты

CWE-476
CWE-89