PT-2018-3561 · Sqlite+4 · Sqlite+4
Publicado
2018-11-10
·
Atualizado
2021-09-23
·
CVE-2018-20346
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
SQLite versions prior to 3.25.3
Description:
The issue is caused by an integer overflow in the FTS3 extension of the SQLite database management system. This overflow can lead to a buffer overflow, allowing remote attackers to execute arbitrary code by running arbitrary SQL statements, such as in certain WebSQL use cases.
Recommendations:
For versions prior to 3.25.3, update to version 3.25.3 or later to resolve the issue. As a temporary workaround, consider disabling the FTS3 extension until a patch is available. Restrict access to FTS3 queries to minimize the risk of exploitation. Avoid using crafted changes to FTS3 shadow tables in SQL statements until the issue is resolved.
Exploit
Correção
Integer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Sqlite
Suse
Ubuntu
Itunes