The getNodeSize function in ext/rtree/rtree.c in SQLite through 3.19.3, as used in GDAL and other products, mishandles undersized RTree blobs in a crafted database, leading to a heap-based buffer over-read or possibly unspecified other impact.
CVSS Details
- CVSS 3.0 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-sqlite | Oct 5, 2017 | Jul 7, 2017 | |
| Apple Osx Sqlite | apple-osx-upgrade-latest | Sep 26, 2017 | Jul 7, 2017 | |
| Debian | debian-upgrade-sqlite3 | Feb 20, 2019 | Jul 7, 2017 | |
| Freebsd | freebsd-upgrade-package-sqlite3 | Aug 8, 2017 | Aug 8, 2017 | |
| Huawei Euleros 2_0_sp2 | huawei-euleros-2_0_sp2-upgrade-sqlitehuawei-euleros-2_0_sp2-upgrade-sqlite-devel | Jul 23, 2019 | Jul 7, 2017 | |
| Huawei Euleros 2_0_sp3 | huawei-euleros-2_0_sp3-upgrade-sqlitehuawei-euleros-2_0_sp3-upgrade-sqlite-devel | Sep 25, 2019 | Jul 7, 2017 | |
| Huawei Euleros 2_0_sp5 | huawei-euleros-2_0_sp5-upgrade-sqlitehuawei-euleros-2_0_sp5-upgrade-sqlite-devel | Jun 27, 2019 | Jul 7, 2017 | |
| Oracle Solaris | oracle-solaris-11-3-upgrade-database-sqlite-3-3-17-0-0-175-3-27-0-3-0oracle-solaris-11-3-upgrade-database-sqlite-3-documentation-3-17-0-0-175-3-27-0-3-0oracle-solaris-11-3-upgrade-runtime-tcl-8-tcl-sqlite-3-3-17-0-0-175-3-27-0-3-0 | Dec 19, 2017 | Jul 7, 2017 | |
| Redhat_linux | — | no-fix-redhat-rpm-package | Jul 9, 2025 | Jul 6, 2017 |
| Suse | — | suse-upgrade-libsqlite3-0suse-upgrade-libsqlite3-0-32bitsuse-upgrade-sqlite3suse-upgrade-sqlite3-devel | May 11, 2019 | Jul 7, 2017 |
| Ubuntu | ubuntu-pro-upgrade-libsqlite3-0ubuntu-pro-upgrade-sqlite3ubuntu-upgrade-libsqlite3-0ubuntu-upgrade-sqlite3 | Jun 20, 2019 | Jul 7, 2017 | |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Jan 20, 2025 | Jul 7, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub