CVE-2019-9937
Gentoo Linux Security Advisory 201908-09
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In SQLite 3.27.2, interleaving reads and writes in a single transaction with an fts5 virtual table will lead to a NULL Pointer Dereference in fts5ChunkIterate in sqlite3.c. This is related to ext/fts5/fts5_hash.c and ext/fts5/fts5_index.c.
En SQLite 3.27.2, las lecturas y escrituras intercaladas en una única transacción con una tabla virtual fts5 conducirá a una desreferencia de puntero NULL en fts5ChunkIterate en sqlite3.c. Esto está relacionado con ext/fts5/fts5_hash.c y ext/fts5/fts5_index.c.
It was discovered that SQLite incorrectly handled certain SQL files. An attacker could possibly use this issue to execute arbitrary code or cause a denial of service. This issue only affected Ubuntu 16.04 LTS. It was discovered that SQLite incorrectly handled certain queries. An attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 18.04 LTS and Ubuntu 18.10. Various other issues were also addressed.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-03-22 CVE Reserved
- 2019-03-22 CVE Published
- 2024-08-04 CVE Updated
- 2025-05-10 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-476: NULL Pointer Dereference
CAPEC
References (13)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/107562 | Third Party Advisory | |
https://lists.debian.org/debian-lts-announce/2020/08/msg00037.html | Mailing List |
|
https://security.netapp.com/advisory/ntap-20190416-0005 | Third Party Advisory |
|
https://www.mail-archive.com/sqlite-users%40mailinglists.sqlite.org/msg114383.html | X_refsource_misc | |
https://www.mail-archive.com/sqlite-users%40mailinglists.sqlite.org/msg114393.html | X_refsource_misc | |
https://www.oracle.com/security-alerts/cpujan2020.html | X_refsource_misc |
|
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html | X_refsource_misc |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://sqlite.org/src/info/45c73deb440496e8 | 2023-11-07 |