Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-0232

Опубликовано: 12 окт. 2023
Источник: redhat
CVSS3: 4.7
EPSS Низкий

Описание

A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service.

Отчет

Red Hat has determined this flaw to be of low impact as successful exploitation may result in a crash (denial of service) of the application and does not impact system-wide stability or lead to arbitrary code execution or memory corruption.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6sqliteOut of support scope
Red Hat Enterprise Linux 7sqliteOut of support scope
Red Hat Enterprise Linux 8mingw-sqliteFix deferred
Red Hat Enterprise Linux 8sqliteFix deferred
Red Hat Enterprise Linux 9sqliteFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2243754sqlite: use-after-free bug in jsonParseAddNodeArray

EPSS

Процентиль: 4%
0.00018
Низкий

4.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.7
ubuntu
около 2 лет назад

A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service.

CVSS3: 4.7
nvd
около 2 лет назад

A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service.

CVSS3: 4.7
debian
около 2 лет назад

A heap use-after-free issue has been identified in SQLite in the jsonP ...

CVSS3: 4.7
github
около 2 лет назад

A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service.

EPSS

Процентиль: 4%
0.00018
Низкий

4.7 Medium

CVSS3