PT-2020-1265 · Sqlite+2 · Sqlite+2

Published

2020-06-06

·

Updated

2024-06-15

·

CVE-2020-13871

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions SQLite version 3.32.2
Description The issue is related to a use-after-free in the resetAccumulator function in select.c, caused by the parse tree rewrite for window functions being too late. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. The estimated number of potentially affected devices worldwide is not specified.
Recommendations For SQLite version 3.32.2, consider updating to a newer version to mitigate the risk, as the current version has a use-after-free issue in the resetAccumulator function. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2148
ALT-PU-2020-2221
ALT-PU-2020-2898
ALT-PU-2021-1906
ALT-PU-2021-2382
ALT-PU-2021-3670
ASB-A-192606047
BDU:2021-00799
BIT-SQLITE-2020-13871
CVE-2020-13871
DLA-2340-1
MGASA-2021-0303
OPENSUSE-SU-2024:11400-1

Affected Products

Alt Linux
Astra Linux
Sqlite