PT-2018-3561 · Sqlite+4 · Sqlite+4
Published
2018-11-10
·
Updated
2021-09-23
·
CVE-2018-20346
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
SQLite versions prior to 3.25.3
Description:
The issue is caused by an integer overflow in the FTS3 extension of the SQLite database management system. This overflow can lead to a buffer overflow, allowing remote attackers to execute arbitrary code by running arbitrary SQL statements, such as in certain WebSQL use cases.
Recommendations:
For versions prior to 3.25.3, update to version 3.25.3 or later to resolve the issue. As a temporary workaround, consider disabling the FTS3 extension until a patch is available. Restrict access to FTS3 queries to minimize the risk of exploitation. Avoid using crafted changes to FTS3 shadow tables in SQL statements until the issue is resolved.
Exploit
Fix
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Sqlite
Suse
Ubuntu
Itunes