PT-2015-6315 · Sqlite Consortium+2 · Sqlite+4

Peter Rutenbar

·

Published

2015-04-29

·

Updated

2020-11-20

·

CVE-2015-3717

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SQLite versions prior to the version included in Apple iOS 8.4 SQLite versions prior to the version included in Apple OS X 10.10.4
Description The issue is related to multiple buffer overflows in the printf functionality in SQLite. This allows remote attackers to execute arbitrary code or cause a denial of service, resulting in an application crash, via unspecified vectors.
Recommendations For SQLite versions used in Apple iOS before 8.4, update to Apple iOS 8.4 or later. For SQLite versions used in Apple OS X before 10.10.4, update to Apple OS X 10.10.4 or later.

Fix

DoS

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1413
CVE-2015-3717
ZDI-15-290

Affected Products

Alt Linux
Os X
Ios
Sqlite
Itunes