In sqlite3_str_vappendf of sqlite3.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege if the user can also inject a printf into a privileged process's SQL with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-153352319
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Oracle Solaris | — | Upgrade runtime/tcl-8/tcl-sqlite-3 to version 3.32.1-11.4.24.0.1.75.1 on Solaris 11.4Upgrade database/sqlite-3/documentation to version 3.32.1-11.4.24.0.1.75.1 on Solaris 11.4Upgrade database/sqlite-3 to version 3.32.1-11.4.24.0.1.75.1 on Solaris 11.4 | Oct 12, 2021 | Aug 17, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub