PT-2021-4561 · Sqlite+6 · Sqlite+6
Ardu
·
Published
2021-07-07
·
Updated
2024-09-30
·
CVE-2021-36690
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
SQLite version 3.36.0
Description
The issue is related to a segmentation fault that can occur in the sqlite3.exe command-line component of SQLite via the idxGetTableInfo function when there is a crafted SQL query. This can cause a denial of service. The vendor disputes the relevance of this report because a sqlite3.exe user already has full privileges.
Recommendations
For SQLite version 3.36.0, this issue was addressed with improved checks.
Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Linuxmint
Apple Macos
Sqlite
Suse
Ubuntu