PT-2020-16662 · Zetetic+1 · Sqlcipher+1

Published

2020-11-07

·

Updated

2024-10-17

·

CVE-2020-27207

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Zetetic SQLCipher versions 4.x before 4.4.1
Description The issue is related to a use-after-free error, specifically involving sqlcipher codec pragma and sqlite3Strlen30 in sqlite3.c. This can lead to a remote denial of service attack. An example of exploitation includes using SQL injection to execute a crafted SQL command sequence, resulting in the reading of unexpected RAM data.
Recommendations For versions prior to 4.4.1, update to version 4.4.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of SQL commands that could lead to the exploitation of the sqlcipher codec pragma and sqlite3Strlen30 functions until a patch is applied.

Fix

DoS

Use After Free

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3229
ALT-PU-2024-14056
CVE-2020-27207

Affected Products

Alt Linux
Sqlcipher