PT-2020-3308 · Sqlite+6 · Sqlite+6

Published

2020-02-21

·

Updated

2024-03-06

·

CVE-2020-9327

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions SQLite version 3.31.1
Description The issue is related to the isAuxiliaryVtabOperator component in the SQLite database management system, which is associated with pointer dereference errors. This can allow a remote attacker to cause a denial of service due to a NULL pointer dereference and segmentation fault, triggered by generated column optimizations.
Recommendations For SQLite version 3.31.1, consider updating to a newer version to mitigate the risk, as the current version contains a flaw in the isAuxiliaryVtabOperator that can lead to a segmentation fault. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1981
ALT-PU-2020-2004
ALT-PU-2020-2898
ALT-PU-2021-1906
ALT-PU-2021-2382
ALT-PU-2021-3670
BDU:2020-03619
BIT-SQLITE-2020-9327
CESA-2020_4442
CVE-2020-9327
MGASA-2021-0303
OPENSUSE-SU-2021:1058-1
OPENSUSE-SU-2021:2320-1
OPENSUSE-SU-2021_1058-1
OPENSUSE-SU-2021_2320-1
RHSA-2020:4442
RHSA-2020_4442
SUSE-SU-2021:2320-1
SUSE-SU-2021:3215-1
USN-4298-1

Affected Products

Alt Linux
Astra Linux
Centos
Red Hat
Sqlite
Suse
Ubuntu