An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "SQLite" component. It allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a crafted SQL statement.
CVSS Details
- CVSS 3.0 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Sqlite | — | Upgrade macOS to the latest version | May 16, 2017 | May 16, 2017 |
| Debian | — | Upgrade sqlite3 | Feb 20, 2019 | May 22, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade sqlite-develUpgrade sqlite | Jun 17, 2020 | May 22, 2017 |
| Suse | — | Upgrade libsqlite3-0Upgrade sqlite3-develUpgrade libsqlite3-0-32bitUpgrade sqlite3 | Nov 26, 2019 | May 22, 2017 |
| Ubuntu | — | Upgrade sqlite3 (Ubuntu Pro)Upgrade libsqlite3-0Upgrade libsqlite3-0 (Ubuntu Pro)Upgrade sqlite3 | Jun 20, 2019 | May 22, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub