Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-35525

Опубликовано: 20 фев. 2020
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

In SQlite 3.31.1, a potential null pointer derreference was found in the INTERSEC query processing.

A NULL pointer dereference flaw was found in select.c of SQLite. An out-of-memory error occurs while an early out on the INTERSECT query is processing. This flaw allows an attacker to execute a potential NULL pointer dereference.

Отчет

This flaw is rated as low because this flaw type of vulnerability is believed to require unlikely circumstances to be able to be exploited, or where a successful exploit would give minimal consequences. Also, this flaw is present in a program’s source code but to which no current or theoretically possible, but unproven, exploitation vectors exist or were found during the technical analysis of the flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6sqliteOut of support scope
Red Hat Enterprise Linux 7sqliteOut of support scope
Red Hat Enterprise Linux 9sqliteNot affected
Red Hat Enterprise Linux 8sqliteFixedRHSA-2022:710825.10.2022
Red Hat Enterprise Linux 8sqliteFixedRHSA-2022:710825.10.2022

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2122324sqlite: Null pointer derreference in src/select.c

EPSS

Процентиль: 39%
0.00172
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 3 года назад

In SQlite 3.31.1, a potential null pointer derreference was found in the INTERSEC query processing.

CVSS3: 7.5
nvd
почти 3 года назад

In SQlite 3.31.1, a potential null pointer derreference was found in the INTERSEC query processing.

CVSS3: 7.5
debian
почти 3 года назад

In SQlite 3.31.1, a potential null pointer derreference was found in t ...

CVSS3: 7.5
github
почти 3 года назад

In SQlite 3.31.1, a potential null pointer derreference was found in the INTERSEC query processing.

rocky
почти 3 года назад

Moderate: sqlite security update

EPSS

Процентиль: 39%
0.00172
Низкий

7.5 High

CVSS3