PT-2019-4852 · Sqlite+4 · Sqlite3+4
Cory Duplantis
·
Publicado
2019-03-22
·
Atualizado
2022-06-13
·
CVE-2019-5018
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Sqlite3 versions 3.26.0 through 3.27.x
Description
The issue is related to an error in the window function of the SQLite database management system. Exploitation of this issue can allow a remote attacker to cause a denial of service. A specially crafted SQL command can trigger a use after free vulnerability, potentially resulting in remote code execution. The problem is caused by an error in the implementation of window functions, starting from the SQLite 3.26 branch.
Recommendations
For versions 3.26.0 through 3.27.x, update to version 3.28 or later to resolve the issue. As a temporary workaround, consider restricting the execution of SQL commands from untrusted sources to minimize the risk of exploitation. Avoid using the window function functionality in SQL commands until the issue is resolved.
Exploit
Correção
RCE
Use After Free
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Centos
Red Hat
Sqlite3
Ubuntu