PT-2018-3561 · Sqlite+4 · Sqlite+4

Published

2018-11-10

·

Updated

2021-09-23

·

CVE-2018-20346

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: SQLite versions prior to 3.25.3
Description: The issue is caused by an integer overflow in the FTS3 extension of the SQLite database management system. This overflow can lead to a buffer overflow, allowing remote attackers to execute arbitrary code by running arbitrary SQL statements, such as in certain WebSQL use cases.
Recommendations: For versions prior to 3.25.3, update to version 3.25.3 or later to resolve the issue. As a temporary workaround, consider disabling the FTS3 extension until a patch is available. Restrict access to FTS3 queries to minimize the risk of exploitation. Avoid using crafted changes to FTS3 shadow tables in SQL statements until the issue is resolved.

Exploit

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2879
ALT-PU-2019-1034
AZL-38458
BDU:2020-04840
CVE-2018-20346
DLA-1613-1
DLA-2340-1
DSA-4352-1
MGASA-2018-0489
OPENSUSE-SU-2019:1159-1
OPENSUSE-SU-2019_1159-1
OPENSUSE-SU-2019_1222-1
SUSE-SU-2019:0788-1
SUSE-SU-2019:0913-1
SUSE-SU-2019:0973-1
SUSE-SU-2019:14003-1
SUSE-SU-2019_0913-1
SUSE-SU-2019_14003-1
SUSE-SU-2021:3215-1
USN-4019-1
USN-4019-2

Affected Products

Alt Linux
Sqlite
Suse
Ubuntu
Itunes