Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-70873

Опубликовано: 12 мар. 2026
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.

A flaw was found in SQLite. This information disclosure vulnerability exists within the zipfile extension, specifically in the zipfileInflate function. A remote attacker could exploit this by providing a specially crafted ZIP file. Successful exploitation could lead to the disclosure of sensitive heap memory information.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10sqliteFix deferred
Red Hat Enterprise Linux 6sqliteOut of support scope
Red Hat Enterprise Linux 7sqliteFix deferred
Red Hat Enterprise Linux 8mingw-sqliteFix deferred
Red Hat Enterprise Linux 8nodejs:22/nodejsFix deferred
Red Hat Enterprise Linux 8nodejs:24/nodejsFix deferred
Red Hat Enterprise Linux 8rust-toolset:rhel8/rustFix deferred
Red Hat Enterprise Linux 8sqliteFix deferred
Red Hat Enterprise Linux 9nodejs:22/nodejsFix deferred
Red Hat Enterprise Linux 9nodejs:24/nodejsFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-908
https://bugzilla.redhat.com/show_bug.cgi?id=2447086sqlite: SQLite: Information Disclosure via Crafted ZIP File

EPSS

Процентиль: 22%
0.00301
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
5 месяцев назад

An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.

CVSS3: 7.5
nvd
5 месяцев назад

An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.

CVSS3: 7.5
msrc
4 месяца назад

An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.

CVSS3: 7.5
debian
5 месяцев назад

An information disclosure issue in the zipfileInflate function in the ...

CVSS3: 7.5
github
5 месяцев назад

An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.

EPSS

Процентиль: 22%
0.00301
Низкий

3.3 Low

CVSS3