Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-19244

Опубликовано: 22 нояб. 2019
Источник: redhat
CVSS3: 7.5

Описание

sqlite3Select in select.c in SQLite 3.30.1 allows a crash if a sub-select uses both DISTINCT and window functions, and also has certain ORDER BY usage.

A flaw was found in the way SQLite handled certain types of SQL queries using DISTINCT, OVER and ORDER BY clauses. A remote attacker could exploit this flaw by providing a malicious SQL query that, when processed by an application linked to SQLite, would crash the application causing a denial of service.

Отчет

This flaw has been rated as having a security impact of Low. The versions of sqlite as shipped with Red Hat Enterprise Linux are compiled without SQLITE_DEBUG, so it's not possible to reproduce the crash. The invalid Mem object may still lead to undefined behaviors, though no notable defects have been observed.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5sqliteOut of support scope
Red Hat Enterprise Linux 6sqliteOut of support scope
Red Hat Enterprise Linux 7sqliteFix deferred
Red Hat Enterprise Linux 8sqliteFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1777945sqlite: allows a crash if a sub-select uses both DISTINCT and window functions and also has certain ORDER BY usage

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 6 лет назад

sqlite3Select in select.c in SQLite 3.30.1 allows a crash if a sub-select uses both DISTINCT and window functions, and also has certain ORDER BY usage.

CVSS3: 7.5
nvd
около 6 лет назад

sqlite3Select in select.c in SQLite 3.30.1 allows a crash if a sub-select uses both DISTINCT and window functions, and also has certain ORDER BY usage.

CVSS3: 7.5
debian
около 6 лет назад

sqlite3Select in select.c in SQLite 3.30.1 allows a crash if a sub-sel ...

CVSS3: 7.5
github
больше 3 лет назад

sqlite3Select in select.c in SQLite 3.30.1 allows a crash if a sub-select uses both DISTINCT and window functions, and also has certain ORDER BY usage.

CVSS3: 7.5
fstec
около 6 лет назад

Уязвимость функции sqlite3Select системы управления базами данных SQLite, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю вызвать отказ в обслуживании

7.5 High

CVSS3