Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-19959

Опубликовано: 23 дек. 2019
Источник: redhat
CVSS3: 7.3
EPSS Низкий

Описание

ext/misc/zipfile.c in SQLite 3.30.1 mishandles certain uses of INSERT INTO in situations involving embedded '\0' characters in filenames, leading to a memory-management error that can be detected by (for example) valgrind.

Отчет

The zip extension was introduced in sqlite-3.22.0, therefore previous versions are not affected by this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5sqliteNot affected
Red Hat Enterprise Linux 6sqliteNot affected
Red Hat Enterprise Linux 7sqliteNot affected
Red Hat Enterprise Linux 8sqliteFixedRHSA-2020:181028.04.2020
Red Hat Enterprise Linux 8sqliteFixedRHSA-2020:181028.04.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-626
https://bugzilla.redhat.com/show_bug.cgi?id=1789595sqlite: mishandles certain uses of INSERT INTO in situations involving embedded '\0' characters in filenames

EPSS

Процентиль: 66%
0.0052
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 6 лет назад

ext/misc/zipfile.c in SQLite 3.30.1 mishandles certain uses of INSERT INTO in situations involving embedded '\0' characters in filenames, leading to a memory-management error that can be detected by (for example) valgrind.

CVSS3: 7.5
nvd
около 6 лет назад

ext/misc/zipfile.c in SQLite 3.30.1 mishandles certain uses of INSERT INTO in situations involving embedded '\0' characters in filenames, leading to a memory-management error that can be detected by (for example) valgrind.

CVSS3: 7.5
debian
около 6 лет назад

ext/misc/zipfile.c in SQLite 3.30.1 mishandles certain uses of INSERT ...

github
больше 3 лет назад

ext/misc/zipfile.c in SQLite 3.30.1 mishandles certain uses of INSERT INTO in situations involving embedded '\0' characters in filenames, leading to a memory-management error that can be detected by (for example) valgrind.

CVSS3: 7.5
fstec
около 6 лет назад

Уязвимость функции zipfile() системы управления базами данных SQLite, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код

EPSS

Процентиль: 66%
0.0052
Низкий

7.3 High

CVSS3