Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-19244

Опубликовано: 22 нояб. 2019
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

sqlite3Select in select.c in SQLite 3.30.1 allows a crash if a sub-select uses both DISTINCT and window functions, and also has certain ORDER BY usage.

A flaw was found in the way SQLite handled certain types of SQL queries using DISTINCT, OVER and ORDER BY clauses. A remote attacker could exploit this flaw by providing a malicious SQL query that, when processed by an application linked to SQLite, would crash the application causing a denial of service.

Отчет

This flaw has been rated as having a security impact of Low. The versions of sqlite as shipped with Red Hat Enterprise Linux are compiled without SQLITE_DEBUG, so it's not possible to reproduce the crash. The invalid Mem object may still lead to undefined behaviors, though no notable defects have been observed.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5sqliteOut of support scope
Red Hat Enterprise Linux 6sqliteOut of support scope
Red Hat Enterprise Linux 7sqliteFix deferred
Red Hat Enterprise Linux 8sqliteFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1777945sqlite: allows a crash if a sub-select uses both DISTINCT and window functions and also has certain ORDER BY usage

EPSS

Процентиль: 88%
0.03333
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 7 лет назад

sqlite3Select in select.c in SQLite 3.30.1 allows a crash if a sub-select uses both DISTINCT and window functions, and also has certain ORDER BY usage.

CVSS3: 7.5
nvd
почти 7 лет назад

sqlite3Select in select.c in SQLite 3.30.1 allows a crash if a sub-select uses both DISTINCT and window functions, and also has certain ORDER BY usage.

msrc
12 месяцев назад

sqlite3Select in select.c in SQLite 3.30.1 allows a crash if a sub-select uses both DISTINCT and window functions, and also has certain ORDER BY usage.

CVSS3: 7.5
debian
почти 7 лет назад

sqlite3Select in select.c in SQLite 3.30.1 allows a crash if a sub-sel ...

CVSS3: 7.5
github
больше 4 лет назад

sqlite3Select in select.c in SQLite 3.30.1 allows a crash if a sub-select uses both DISTINCT and window functions, and also has certain ORDER BY usage.

EPSS

Процентиль: 88%
0.03333
Низкий

7.5 High

CVSS3