PT-2019-5082 · Sqlite+7 · Sqlite+7

Publicado

2019-12-24

·

Atualizado

2022-04-15

·

CVE-2019-19925

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions SQLite version 3.30.1
Description The issue is related to the zipfileUpdate() function in SQLite, which mishandles a NULL pathname during an update of a ZIP archive. This can be exploited by a remote attacker to cause a denial of service.
Recommendations For SQLite version 3.30.1, consider disabling the zipfileUpdate() function until a patch is available to prevent potential exploitation. Restrict access to the zipfile.c module to minimize the risk of denial of service attacks. Avoid using the zipfileUpdate() function with NULL pathnames until the issue is resolved.

Exploit

Correção

DoS

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2020-1088
ALT-PU-2020-1457
ALT-PU-2020-1521
ALT-PU-2020-1707
ALT-PU-2020-2094
ALT-PU-2020-2183
ALT-PU-2020-2441
ALT-PU-2020-2898
BDU:2020-01748
CESA-2020_1810
CVE-2019-19925
DSA-4638-1
MGASA-2020-0123
OPENSUSE-SU-2020:0189-1
OPENSUSE-SU-2020:0210-1
OPENSUSE-SU-2020:0233-1
OPENSUSE-SU-2020_0189-1
OPENSUSE-SU-2021:1058-1
OPENSUSE-SU-2021:2320-1
OPENSUSE-SU-2021_1058-1
OPENSUSE-SU-2021_2320-1
RHSA-2020:0514
RHSA-2020:1810
RHSA-2020_0514
RHSA-2020_1810
SUSE-SU-2021:2320-1
SUSE-SU-2021:3215-1
USN-4298-1

Produtos afetados

Alt Linux
Astra Linux
Centos
Google Chrome
Red Hat
Sqlite
Suse
Ubuntu