CPANSA-DBD-SQLite-2020-15358: DBD-SQLite vulnerability
Publisher | giterlizzi | Document category | csaf_security_advisory |
---|---|---|---|
Initial release date | 2020-06-27T00:00:00 | Engine | CSAF Perl Toolkit 0.25 |
Current release date | 2020-06-27T00:00:00 | Build Date | |
Current version | 1 | Status | final |
CVSS v3.1 Base Score | 5.5 | Severity | Medium |
Original language | Language | en | |
Also referred to |
Vulnerability Description
In SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation.
Vulnerabilities
CVE-2020-15358
Vulnerability DescriptionIn SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation.
Weakness | CWE-787 : Out-of-bounds Write |
---|
Product status
Known affected
Product | Score | ||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
DBD-SQLite less than 1.65_03 |
|
Fixed
- DBD-SQLite greater than or equal 1.65_03
giterlizzi
Namespace: https://github.com/giterlizzi/
gdt@cpan.org
References
- CPANSA-DBD-SQLite-2020-15358 JSON self
https://raw.githubusercontent.com/giterlizzi/perl-CPANSA-CSAF/develop/csaf/white/2020/cpansa-dbd-sqlite-2020-15358.json - https://www.sqlite.org/src/info/10fa79d00f8091e5 external
https://www.sqlite.org/src/info/10fa79d00f8091e5 - https://www.sqlite.org/src/timeline?p=version-3.32.3&bt=version-3.32.2 external
https://www.sqlite.org/src/timeline?p=version-3.32.3&bt=version-3.32.2 - https://www.sqlite.org/src/tktview?name=8f157e8010 external
https://www.sqlite.org/src/tktview?name=8f157e8010 - https://security.netapp.com/advisory/ntap-20200709-0001/ external
https://security.netapp.com/advisory/ntap-20200709-0001/ - https://security.gentoo.org/glsa/202007-26 external
https://security.gentoo.org/glsa/202007-26 - https://usn.ubuntu.com/4438-1/ external
https://usn.ubuntu.com/4438-1/ - https://www.oracle.com/security-alerts/cpuoct2020.html external
https://www.oracle.com/security-alerts/cpuoct2020.html - https://support.apple.com/kb/HT211931 external
https://support.apple.com/kb/HT211931 - https://support.apple.com/kb/HT211844 external
https://support.apple.com/kb/HT211844 - https://support.apple.com/kb/HT211850 external
https://support.apple.com/kb/HT211850 - https://support.apple.com/kb/HT211843 external
https://support.apple.com/kb/HT211843 - https://support.apple.com/kb/HT211847 external
https://support.apple.com/kb/HT211847 - http://seclists.org/fulldisclosure/2020/Nov/19 external
http://seclists.org/fulldisclosure/2020/Nov/19 - http://seclists.org/fulldisclosure/2020/Nov/22 external
http://seclists.org/fulldisclosure/2020/Nov/22 - http://seclists.org/fulldisclosure/2020/Nov/20 external
http://seclists.org/fulldisclosure/2020/Nov/20 - http://seclists.org/fulldisclosure/2020/Dec/32 external
http://seclists.org/fulldisclosure/2020/Dec/32 - https://www.oracle.com/security-alerts/cpujan2021.html external
https://www.oracle.com/security-alerts/cpujan2021.html - https://support.apple.com/kb/HT212147 external
https://support.apple.com/kb/HT212147 - http://seclists.org/fulldisclosure/2021/Feb/14 external
http://seclists.org/fulldisclosure/2021/Feb/14 - https://www.oracle.com/security-alerts/cpuApr2021.html external
https://www.oracle.com/security-alerts/cpuApr2021.html - https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf external
https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf - https://www.oracle.com/security-alerts/cpuapr2022.html external
https://www.oracle.com/security-alerts/cpuapr2022.html - CVE-2020-15358 (NVD) external
https://nvd.nist.gov/vuln/detail/CVE-2020-15358
Revision history
Version | Date of the revision | Summary of the revision |
---|---|---|
1 | Sat Jun 27 00:00:00 2020 | First release |
Sharing rules
TLP:WHITE
For the TLP version see: https://www.first.org/tlp/