Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-16168

Опубликовано: 15 авг. 2019
Источник: redhat
CVSS3: 6.5

Описание

In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validation of a sqlite_stat1 sz field, aka a "severe division by zero in the query planner."

Отчет

The SQLite package as shipped with Red Hat Enterprise Linux 7 and previous versions are not affected by this flaw. The bug was introduced on sqlite-3.8.5 while Red Hat Enterprise Linux 7 and previous releases ships sqlite <= 3.7.17.

Меры по смягчению последствий

An user can mitigate the risk of this vulnerability by:

  1. Avoid using ANALYZE command on queries;
  2. Disabling the PRAGMA optimize for affected SQLite instances;

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5sqliteNot affected
Red Hat Enterprise Linux 6sqliteNot affected
Red Hat Enterprise Linux 7sqliteNot affected
Red Hat Enterprise Linux 8sqliteFixedRHSA-2020:444204.11.2020
Red Hat Enterprise Linux 8mingw-binutilsFixedRHSA-2021:196818.05.2021
Red Hat Enterprise Linux 8mingw-bzip2FixedRHSA-2021:196818.05.2021
Red Hat Enterprise Linux 8mingw-filesystemFixedRHSA-2021:196818.05.2021
Red Hat Enterprise Linux 8mingw-sqliteFixedRHSA-2021:196818.05.2021
Red Hat Enterprise Linux 8sqliteFixedRHSA-2020:444204.11.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-369
https://bugzilla.redhat.com/show_bug.cgi?id=1768986sqlite: Division by zero in whereLoopAddBtreeIndex in sqlite3.c

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 6 лет назад

In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validation of a sqlite_stat1 sz field, aka a "severe division by zero in the query planner."

CVSS3: 6.5
nvd
около 6 лет назад

In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validation of a sqlite_stat1 sz field, aka a "severe division by zero in the query planner."

CVSS3: 6.5
msrc
около 1 года назад

Описание отсутствует

CVSS3: 6.5
debian
около 6 лет назад

In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can cras ...

suse-cvrf
почти 6 лет назад

Security update for sqlite3

6.5 Medium

CVSS3