Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-10989

Опубликовано: 07 июл. 2017
Источник: ubuntu
Приоритет: negligible
EPSS Низкий
CVSS2: 7.5
CVSS3: 9.8

Описание

The getNodeSize function in ext/rtree/rtree.c in SQLite through 3.19.3, as used in GDAL and other products, mishandles undersized RTree blobs in a crafted database, leading to a heap-based buffer over-read or possibly unspecified other impact.

РелизСтатусПримечание
artful

not-affected

3.19.3-3
bionic

not-affected

3.22.0-1
cosmic

not-affected

3.22.0-1
devel

not-affected

3.22.0-1
disco

not-affected

3.22.0-1
esm-infra-legacy/trusty

released

3.8.2-1ubuntu2.2+esm1
esm-infra-legacy/xenial

released

3.11.0-1ubuntu1.2
esm-infra/bionic

not-affected

3.22.0-1
esm-infra/xenial

released

3.11.0-1ubuntu1.2
precise/esm

not-affected

code not present

Показывать по

EPSS

Процентиль: 95%
0.08609
Низкий

7.5 High

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 3.6
redhat
около 9 лет назад

The getNodeSize function in ext/rtree/rtree.c in SQLite through 3.19.3, as used in GDAL and other products, mishandles undersized RTree blobs in a crafted database, leading to a heap-based buffer over-read or possibly unspecified other impact.

CVSS3: 9.8
nvd
около 9 лет назад

The getNodeSize function in ext/rtree/rtree.c in SQLite through 3.19.3, as used in GDAL and other products, mishandles undersized RTree blobs in a crafted database, leading to a heap-based buffer over-read or possibly unspecified other impact.

msrc
11 месяцев назад

The getNodeSize function in ext/rtree/rtree.c in SQLite through 3.19.3, as used in GDAL and other products, mishandles undersized RTree blobs in a crafted database, leading to a heap-based buffer over-read or possibly unspecified other impact.

CVSS3: 9.8
debian
около 9 лет назад

The getNodeSize function in ext/rtree/rtree.c in SQLite through 3.19.3 ...

CVSS3: 9.8
github
около 4 лет назад

The getNodeSize function in ext/rtree/rtree.c in SQLite through 3.19.3, as used in GDAL and other products, mishandles undersized RTree blobs in a crafted database, leading to a heap-based buffer over-read or possibly unspecified other impact.

EPSS

Процентиль: 95%
0.08609
Низкий

7.5 High

CVSS2

9.8 Critical

CVSS3