Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-3415

Опубликовано: 24 апр. 2015
Источник: ubuntu
Приоритет: low
CVSS2: 7.5

Описание

The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly implement comparison operators, which allows context-dependent attackers to cause a denial of service (invalid free operation) or possibly have unspecified other impact via a crafted CHECK clause, as demonstrated by CHECK(0&O>O) in a CREATE TABLE statement.

РелизСтатусПримечание
artful

ignored

end of life
bionic

not-affected

code not present
cosmic

not-affected

code not present
devel

not-affected

code not present
esm-apps/bionic

not-affected

code not present
esm-apps/xenial

not-affected

code not present
esm-infra-legacy/trusty

not-affected

code not present
lucid

ignored

end of life
precise

ignored

end of life
precise/esm

DNE

precise was needs-triage

Показывать по

РелизСтатусПримечание
artful

not-affected

3.8.10.2-1
bionic

not-affected

3.8.10.2-1
cosmic

not-affected

3.8.10.2-1
devel

not-affected

3.8.10.2-1
esm-infra-legacy/trusty

not-affected

code not present
esm-infra/bionic

not-affected

3.8.10.2-1
esm-infra/xenial

not-affected

3.8.10.2-1
lucid

ignored

end of life
precise

not-affected

code not present
precise/esm

not-affected

code not present

Показывать по

7.5 High

CVSS2

Связанные уязвимости

redhat
почти 11 лет назад

The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly implement comparison operators, which allows context-dependent attackers to cause a denial of service (invalid free operation) or possibly have unspecified other impact via a crafted CHECK clause, as demonstrated by CHECK(0&O>O) in a CREATE TABLE statement.

nvd
почти 11 лет назад

The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly implement comparison operators, which allows context-dependent attackers to cause a denial of service (invalid free operation) or possibly have unspecified other impact via a crafted CHECK clause, as demonstrated by CHECK(0&O>O) in a CREATE TABLE statement.

debian
почти 11 лет назад

The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not ...

github
больше 3 лет назад

The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly implement comparison operators, which allows context-dependent attackers to cause a denial of service (invalid free operation) or possibly have unspecified other impact via a crafted CHECK clause, as demonstrated by CHECK(0&O>O) in a CREATE TABLE statement.

oracle-oval
больше 10 лет назад

ELSA-2015-1635: sqlite security update (MODERATE)

7.5 High

CVSS2