PT-2019-4852 · Sqlite+4 · Sqlite3+4

Cory Duplantis

·

Publicado

2019-03-22

·

Atualizado

2022-06-13

·

CVE-2019-5018

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Sqlite3 versions 3.26.0 through 3.27.x
Description The issue is related to an error in the window function of the SQLite database management system. Exploitation of this issue can allow a remote attacker to cause a denial of service. A specially crafted SQL command can trigger a use after free vulnerability, potentially resulting in remote code execution. The problem is caused by an error in the implementation of window functions, starting from the SQLite 3.26 branch.
Recommendations For versions 3.26.0 through 3.27.x, update to version 3.28 or later to resolve the issue. As a temporary workaround, consider restricting the execution of SQL commands from untrusted sources to minimize the risk of exploitation. Avoid using the window function functionality in SQL commands until the issue is resolved.

Exploit

Correção

RCE

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-1492
BDU:2020-01436
CESA-2020_4442
CVE-2019-5018
RHSA-2020:4442
RHSA-2020_4442
USN-4205-1

Produtos afetados

Alt Linux
Centos
Red Hat
Sqlite3
Ubuntu