Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-10989

Опубликовано: 06 июл. 2017
Источник: redhat
CVSS3: 3.6

Описание

The getNodeSize function in ext/rtree/rtree.c in SQLite through 3.19.3, as used in GDAL and other products, mishandles undersized RTree blobs in a crafted database, leading to a heap-based buffer over-read or possibly unspecified other impact.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5sqliteNot affected
Red Hat Enterprise Linux 6sqliteWill not fix
Red Hat Enterprise Linux 7sqliteWill not fix
Red Hat Enterprise Virtualization 3mingw-virt-viewerUnder investigation

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1469672sqlite: Heap-buffer overflow in the getNodeSize function

3.6 Low

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 8 лет назад

The getNodeSize function in ext/rtree/rtree.c in SQLite through 3.19.3, as used in GDAL and other products, mishandles undersized RTree blobs in a crafted database, leading to a heap-based buffer over-read or possibly unspecified other impact.

CVSS3: 9.8
nvd
больше 8 лет назад

The getNodeSize function in ext/rtree/rtree.c in SQLite through 3.19.3, as used in GDAL and other products, mishandles undersized RTree blobs in a crafted database, leading to a heap-based buffer over-read or possibly unspecified other impact.

msrc
5 месяцев назад

The getNodeSize function in ext/rtree/rtree.c in SQLite through 3.19.3, as used in GDAL and other products, mishandles undersized RTree blobs in a crafted database, leading to a heap-based buffer over-read or possibly unspecified other impact.

CVSS3: 9.8
debian
больше 8 лет назад

The getNodeSize function in ext/rtree/rtree.c in SQLite through 3.19.3 ...

CVSS3: 9.8
github
больше 3 лет назад

The getNodeSize function in ext/rtree/rtree.c in SQLite through 3.19.3, as used in GDAL and other products, mishandles undersized RTree blobs in a crafted database, leading to a heap-based buffer over-read or possibly unspecified other impact.

3.6 Low

CVSS3

Уязвимость CVE-2017-10989