PT-2025-29558 · Sqlite+14 · Sqlite+14
CVSS v3.1
7.7
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
SQLite versions prior to 3.50.2
Description
An issue exists where the number of aggregate terms in a query can exceed the number of available columns, leading to integer truncation. This flaw can result in memory corruption, potentially causing the system to crash (denial of service) or allowing an attacker to execute arbitrary code. Real-world exploitation has been observed in Siemens RUGGEDCOM CROSSBOW SAC, where the issue was used to achieve privilege escalation and lateral movement within networked industrial systems. Additionally, the vulnerability affects the
WinSqlite3.dll component in Windows environments.Recommendations
Update to version 3.50.2 or above.
As a temporary workaround, consider bundling updated SQLite libraries to replace vulnerable versions of
WinSqlite3.dll.Exploit
Fix
LPE
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Debian
Ibm Aix
Linuxmint
Apple Macos
Mysql Server
Red Hat
Red Os
Rocky Linux
Sqlite
Suse
Ubuntu