SQLite 3.25.2, when queries are run on a table with a malformed PRIMARY KEY, allows remote attackers to cause a denial of service (application crash) by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases).
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Itunes | — | Upgrade Apple iTunes to the latest version | Jan 25, 2019 | Jan 24, 2019 |
| Apple Osx Sqlite | — | Upgrade macOS to the latest version | Jan 23, 2019 | Jan 23, 2019 |
| Debian | — | Upgrade sqlite3 | Jul 30, 2024 | Apr 3, 2019 |
| Ubuntu | — | Upgrade sqlite3Upgrade libsqlite3-0 | Jun 20, 2019 | Apr 3, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub