PT-2020-10376 · Sqlite+6 · Sqlite+6

Published

2020-01-02

·

Updated

2022-10-07

·

CVE-2019-20218

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions SQLite version 3.30.1
Description The issue is related to the selectExpander function in the select.c file of SQLite. This function proceeds with WITH stack unwinding even after a parsing error occurs.
Recommendations For SQLite version 3.30.1, consider updating to a newer version that addresses this issue, as the current version may lead to unexpected behavior due to the parsing error not being properly handled. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Handling of Exceptional Conditions

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1088
ALT-PU-2020-2094
ALT-PU-2020-2183
CESA-2020_4442
CVE-2019-20218
DLA-2340-1
DLA-2340-2
OPENSUSE-SU-2021:1058-1
OPENSUSE-SU-2021:2320-1
OPENSUSE-SU-2021_1058-1
OPENSUSE-SU-2021_2320-1
RHSA-2020:4442
RHSA-2020_4442
SUSE-SU-2021:14771-1
SUSE-SU-2021:2320-1
SUSE-SU-2021:3215-1
SUSE-SU-2021_14771-1
USN-4298-1

Affected Products

Alt Linux
Astra Linux
Centos
Red Hat
Sqlite
Suse
Ubuntu