Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-3415

Опубликовано: 24 апр. 2015
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 7.5

Описание

The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly implement comparison operators, which allows context-dependent attackers to cause a denial of service (invalid free operation) or possibly have unspecified other impact via a crafted CHECK clause, as demonstrated by CHECK(0&O>O) in a CREATE TABLE statement.

РелизСтатусПримечание
artful

ignored

end of life
bionic

not-affected

code not present
cosmic

not-affected

code not present
devel

not-affected

code not present
esm-apps/bionic

not-affected

code not present
esm-apps/xenial

not-affected

code not present
esm-infra-legacy/trusty

not-affected

code not present
lucid

ignored

end of life
precise

ignored

end of life
precise/esm

DNE

precise was needs-triage

Показывать по

РелизСтатусПримечание
artful

not-affected

3.8.10.2-1
bionic

not-affected

3.8.10.2-1
cosmic

not-affected

3.8.10.2-1
devel

not-affected

3.8.10.2-1
esm-infra-legacy/trusty

not-affected

code not present
esm-infra/bionic

not-affected

3.8.10.2-1
esm-infra/xenial

not-affected

3.8.10.2-1
lucid

ignored

end of life
precise

not-affected

code not present
precise/esm

not-affected

code not present

Показывать по

EPSS

Процентиль: 91%
0.07077
Низкий

7.5 High

CVSS2

Связанные уязвимости

redhat
около 10 лет назад

The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly implement comparison operators, which allows context-dependent attackers to cause a denial of service (invalid free operation) or possibly have unspecified other impact via a crafted CHECK clause, as demonstrated by CHECK(0&O>O) in a CREATE TABLE statement.

nvd
около 10 лет назад

The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly implement comparison operators, which allows context-dependent attackers to cause a denial of service (invalid free operation) or possibly have unspecified other impact via a crafted CHECK clause, as demonstrated by CHECK(0&O>O) in a CREATE TABLE statement.

debian
около 10 лет назад

The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not ...

github
около 3 лет назад

The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly implement comparison operators, which allows context-dependent attackers to cause a denial of service (invalid free operation) or possibly have unspecified other impact via a crafted CHECK clause, as demonstrated by CHECK(0&O>O) in a CREATE TABLE statement.

oracle-oval
почти 10 лет назад

ELSA-2015-1635: sqlite security update (MODERATE)

EPSS

Процентиль: 91%
0.07077
Низкий

7.5 High

CVSS2