PT-2019-5082 · Sqlite+7 · Sqlite+7

Published

2019-12-24

·

Updated

2022-04-15

·

CVE-2019-19925

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions SQLite version 3.30.1
Description The issue is related to the zipfileUpdate() function in SQLite, which mishandles a NULL pathname during an update of a ZIP archive. This can be exploited by a remote attacker to cause a denial of service.
Recommendations For SQLite version 3.30.1, consider disabling the zipfileUpdate() function until a patch is available to prevent potential exploitation. Restrict access to the zipfile.c module to minimize the risk of denial of service attacks. Avoid using the zipfileUpdate() function with NULL pathnames until the issue is resolved.

Exploit

Fix

DoS

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1088
ALT-PU-2020-1457
ALT-PU-2020-1521
ALT-PU-2020-1707
ALT-PU-2020-2094
ALT-PU-2020-2183
ALT-PU-2020-2441
ALT-PU-2020-2898
BDU:2020-01748
CESA-2020_1810
CVE-2019-19925
DSA-4638-1
MGASA-2020-0123
OPENSUSE-SU-2020:0189-1
OPENSUSE-SU-2020:0210-1
OPENSUSE-SU-2020:0233-1
OPENSUSE-SU-2020_0189-1
OPENSUSE-SU-2021:1058-1
OPENSUSE-SU-2021:2320-1
OPENSUSE-SU-2021_1058-1
OPENSUSE-SU-2021_2320-1
RHSA-2020:0514
RHSA-2020:1810
RHSA-2020_0514
RHSA-2020_1810
SUSE-SU-2021:2320-1
SUSE-SU-2021:3215-1
USN-4298-1

Affected Products

Alt Linux
Astra Linux
Centos
Google Chrome
Red Hat
Sqlite
Suse
Ubuntu