Описание
SQLite through 3.31.1 allows attackers to cause a denial of service (segmentation fault) via a malformed window-function query because the AggInfo object's initialization is mishandled.
Отчет
It seems like this issue existed since sqlite-3.25.0, when window function (https://www.sqlite.org/windowfunctions.html) was added, but it lead to segmentation fault after https://www3.sqlite.org/cgi/src/info/712e47714863a8ed was committed, which could result in denial of service. This commit is a part of sqlite-3.30 release. Therefore previous versions are not vulnerable to this flaw.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 5 | sqlite | Not affected | ||
| Red Hat Enterprise Linux 6 | sqlite | Not affected | ||
| Red Hat Enterprise Linux 7 | sqlite | Not affected | ||
| Red Hat Enterprise Linux 8 | sqlite | Not affected | ||
| Red Hat Openshift Data Foundation 4.19 | registry.redhat.io/odf4/cephcsi-rhel9 | Fixed | RHSA-2025:16504 | 23.09.2025 |
| Red Hat Openshift Data Foundation 4.19 | registry.redhat.io/odf4/cephcsi-rhel9-operator | Fixed | RHSA-2025:16504 | 23.09.2025 |
| Red Hat Openshift Data Foundation 4.19 | registry.redhat.io/odf4/mcg-core-rhel9 | Fixed | RHSA-2025:16504 | 23.09.2025 |
| Red Hat Openshift Data Foundation 4.19 | registry.redhat.io/odf4/mcg-rhel9-operator | Fixed | RHSA-2025:16504 | 23.09.2025 |
| Red Hat Openshift Data Foundation 4.19 | registry.redhat.io/odf4/ocs-client-console-rhel9 | Fixed | RHSA-2025:16504 | 23.09.2025 |
| Red Hat Openshift Data Foundation 4.19 | registry.redhat.io/odf4/ocs-client-rhel9-operator | Fixed | RHSA-2025:16504 | 23.09.2025 |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
SQLite through 3.31.1 allows attackers to cause a denial of service (segmentation fault) via a malformed window-function query because the AggInfo object's initialization is mishandled.
SQLite through 3.31.1 allows attackers to cause a denial of service (segmentation fault) via a malformed window-function query because the AggInfo object's initialization is mishandled.
SQLite through 3.31.1 allows attackers to cause a denial of service (s ...
SQLite through 3.31.1 allows attackers to cause a denial of service (segmentation fault) via a malformed window-function query because the AggInfo object's initialization is mishandled.
7.5 High
CVSS3