Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-9937

Опубликовано: 18 мар. 2019
Источник: redhat
CVSS3: 5.3

Описание

In SQLite 3.27.2, interleaving reads and writes in a single transaction with an fts5 virtual table will lead to a NULL Pointer Dereference in fts5ChunkIterate in sqlite3.c. This is related to ext/fts5/fts5_hash.c and ext/fts5/fts5_index.c.

A vulnerability was found in SQLite due to a NULL pointer dereference in the fts5ChunkIterate function within sqlite3.c, where an attacker could exploit this flaw by creating a specially crafted table, causing the application to crash and resulting in a denial of service condition.

Отчет

This vulnerability in the SQLite3 database engine is rated as Low Severity because of its technical nature and severely limited impact, this flaw is a NULL Pointer Dereference (CWE-476) that occurs within the code that handles full text search tables, specifically the fts5 virtual table functionality. The issue is triggered by specific, non-standard actions: interleaving read and write operations within a single database transaction when interacting with an fts5 table. While this condition can be exploited remotely by an unauthenticated user to cause the issue, the inherent mechanism of a NULL pointer dereference almost exclusively leads to a crash of the affected process. Therefore, the attack's outcome is contained to a low impact Denial of Service (DoS), meaning the database service temporarily stops working, but the attacker gains no ability to steal information, tamper with data, or execute unauthorized code on the host system. This issue did not affect the versions of sqlite as shipped with Red Hat Enterprise Linux 6 and 7 as they did not include support for fts5.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5sqliteNot affected
Red Hat Enterprise Linux 6sqliteNot affected
Red Hat Enterprise Linux 7sqliteNot affected
Red Hat Enterprise Linux 8sqliteFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1692357sqlite: null-pointer dereference in function fts5ChunkIterate in sqlite3.c

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

In SQLite 3.27.2, interleaving reads and writes in a single transaction with an fts5 virtual table will lead to a NULL Pointer Dereference in fts5ChunkIterate in sqlite3.c. This is related to ext/fts5/fts5_hash.c and ext/fts5/fts5_index.c.

CVSS3: 7.5
nvd
больше 7 лет назад

In SQLite 3.27.2, interleaving reads and writes in a single transaction with an fts5 virtual table will lead to a NULL Pointer Dereference in fts5ChunkIterate in sqlite3.c. This is related to ext/fts5/fts5_hash.c and ext/fts5/fts5_index.c.

CVSS3: 7.5
debian
больше 7 лет назад

In SQLite 3.27.2, interleaving reads and writes in a single transactio ...

CVSS3: 7.5
github
больше 4 лет назад

In SQLite 3.27.2, interleaving reads and writes in a single transaction with an fts5 virtual table will lead to a NULL Pointer Dereference in fts5ChunkIterate in sqlite3.c. This is related to ext/fts5/fts5_hash.c and ext/fts5/fts5_index.c.

CVSS3: 7.5
fstec
больше 7 лет назад

Уязвимость компонентов ext/fts5/fts5_hash.c и ext/fts5/fts5_index.c системы управления базами данных SQLite, позволяющая нарушителю вызвать отказ в обслуживании

5.3 Medium

CVSS3