SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases). This is a different vulnerability than CVE-2018-20346.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Itunes | — | Upgrade Apple iTunes to the latest version | Jan 25, 2019 | Jan 24, 2019 |
| Apple Osx Sqlite | — | Upgrade macOS to the latest version | Jan 23, 2019 | Jan 23, 2019 |
| Debian | — | Upgrade sqlite3 | Aug 7, 2020 | Apr 3, 2019 |
| Suse | — | Upgrade sqlite3Upgrade libsqlite3-0-32bitUpgrade libsqlite3-0Upgrade sqlite3-devel | Apr 10, 2019 | Apr 3, 2019 |
| Ubuntu | — | Upgrade libsqlite3-0 (Ubuntu Pro)Upgrade libsqlite3-0Upgrade sqlite3Upgrade sqlite3 (Ubuntu Pro) | Jun 20, 2019 | Apr 3, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub