sqlite: Multiple flaws in sqlite which can be triggered via corrupted internal databases (Magellan)
Published Apr 3, 2019
7.5
HIGHCVSS 3.0
EPSS 6.95%
Description
SQLite 3.25.2, when queries are run on a table with a malformed PRIMARY KEY, allows remote attackers to cause a denial of service (application crash) by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases).
Affected products
No data.
No data.
Red Hat Enterprise Linux 5
sqlite
Not affected
Red Hat Enterprise Linux 6
sqlite
Not affected
Red Hat Enterprise Linux 7
sqlite
Not affected
Red Hat Enterprise Linux 8
sqlite
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | sqlite | Not affected | n/a |
| Red Hat Enterprise Linux 6 | sqlite | Not affected | n/a |
| Red Hat Enterprise Linux 7 | sqlite | Not affected | n/a |
| Red Hat Enterprise Linux 8 | sqlite | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw does not affect the versions of sqlite package shipped with Red Hat Enterprise Linux 5, 6 and 7. This flaw in sqlite can be exploited by attackers only if they are able to run arbitrary SQL statements on the sqlite database. For more information please see https://bugzilla.redhat.com/show_bug.cgi?id=1659379#c12
References (29)
- http://seclists.org/fulldisclosure/2019/Jan/62 x_refsource_MISCMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2019/Jan/64 x_refsource_MISCMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2019/Jan/66 x_refsource_MISCMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2019/Jan/67 x_refsource_MISCMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2019/Jan/68 x_refsource_MISCMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2019/Jan/69 x_refsource_MISCMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/106698 x_refsource_MISCThird Party AdvisoryVDB Entry
- https://access.redhat.com/articles/3758321
- https://access.redhat.com/security/cve/CVE-2018-20505 Vendor Advisory
- https://blade.tencent.com/magellan/index_en.html
- https://bugzilla.redhat.com/show_bug.cgi?id=1659379 Issue Tracking
- https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html
- https://nvd.nist.gov/vuln/detail/CVE-2018-20505
- https://seclists.org/bugtraq/2019/Jan/28 x_refsource_MISCMailing ListThird Party Advisory
- https://seclists.org/bugtraq/2019/Jan/29 x_refsource_MISCMailing ListThird Party Advisory
- https://seclists.org/bugtraq/2019/Jan/31 x_refsource_MISCMailing ListThird Party Advisory
- https://seclists.org/bugtraq/2019/Jan/32 x_refsource_MISCMailing ListThird Party Advisory
- https://seclists.org/bugtraq/2019/Jan/33 x_refsource_MISCMailing ListThird Party Advisory
- https://seclists.org/bugtraq/2019/Jan/39 x_refsource_MISCMailing ListThird Party Advisory
- https://security.netapp.com/advisory/ntap-20190502-0004/ x_refsource_CONFIRMThird Party Advisory
- https://sqlite.org/src/info/1a84668dcfdebaf12415d x_refsource_MISCExploitVendor Advisory
- https://support.apple.com/kb/HT209443 x_refsource_MISCVendor Advisory
- https://support.apple.com/kb/HT209446 x_refsource_MISCVendor Advisory
- https://support.apple.com/kb/HT209447 x_refsource_MISCVendor Advisory
- https://support.apple.com/kb/HT209448 x_refsource_MISCVendor Advisory
- https://support.apple.com/kb/HT209450 x_refsource_MISCVendor Advisory
- https://support.apple.com/kb/HT209451 x_refsource_MISCVendor Advisory
- https://usn.ubuntu.com/4019-1/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2018-20505
Change history (0)
No recorded changes yet.