sqlite: fts3: improve shadow table corruption detection
Published Dec 10, 2019
8.8
HIGHCVSS 3.1
EPSS 3.95%
Description
Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<79.0.3945.79
- Version
Configuration 2
- 30
- 31
Configuration 3
- 3.11
- 4.2
- 8.0
- 6.0
- 7.0
- 7.7
- 8.1
- 8.2
- 8.4
- 6.0
- 7.0
- 7.7
- 8.2
- 8.4
- 7.7
- 8.2
- 8.4
- 6.0
- 7.0
Configuration 4
- 14.04
- 16.04
- 18.04
- 19.10
Configuration 5
- n/a
Running on/with
- 12.0
Configuration 6
- 15.0
Configuration 7
- 9.0
- 10.0
Configuration 8
- 1.14.0
No data.
Red Hat Ansible Tower 3.4 for RHEL 7
ansible-tower-34/ansible-tower-memcached:1.4.15-28
Fixed · RHBA-2020:0547
Red Hat Ansible Tower 3.4 for RHEL 7
ansible-tower-35/ansible-tower-memcached:1.4.15-28
Fixed · RHBA-2020:0547
Red Hat Ansible Tower 3.4 for RHEL 7
ansible-tower-37/ansible-tower-memcached-rhel7:1.4.15-28
Fixed · RHBA-2020:0547
Red Hat Enterprise Linux 6 Supplementary
chromium-browser-0:79.0.3945.79-1.el6_10
Fixed · RHSA-2019:4238
Red Hat Enterprise Linux 7
sqlite-0:3.7.17-8.el7_7.1
Fixed · RHSA-2020:0227
Red Hat Enterprise Linux 7.6 Extended Update Support
sqlite-0:3.7.17-8.el7_6.1
Fixed · RHSA-2020:2014
Red Hat Enterprise Linux 8
sqlite-0:3.26.0-4.el8_1
Fixed · RHSA-2020:0273
Red Hat Enterprise Linux 8
sqlite-0:3.26.0-4.el8_1
Fixed · RHSA-2020:0273
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions
sqlite-0:3.26.0-4.el8_0
Fixed · RHSA-2020:0229
Red Hat Enterprise Linux 5
sqlite
Not affected
Red Hat Enterprise Linux 6
sqlite
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ansible Tower 3.4 for RHEL 7 | ansible-tower-34/ansible-tower-memcached:1.4.15-28 | Fixed | RHBA-2020:0547 |
| Red Hat Ansible Tower 3.4 for RHEL 7 | ansible-tower-35/ansible-tower-memcached:1.4.15-28 | Fixed | RHBA-2020:0547 |
| Red Hat Ansible Tower 3.4 for RHEL 7 | ansible-tower-37/ansible-tower-memcached-rhel7:1.4.15-28 | Fixed | RHBA-2020:0547 |
| Red Hat Enterprise Linux 6 Supplementary | chromium-browser-0:79.0.3945.79-1.el6_10 | Fixed | RHSA-2019:4238 |
| Red Hat Enterprise Linux 7 | sqlite-0:3.7.17-8.el7_7.1 | Fixed | RHSA-2020:0227 |
| Red Hat Enterprise Linux 7.6 Extended Update Support | sqlite-0:3.7.17-8.el7_6.1 | Fixed | RHSA-2020:2014 |
| Red Hat Enterprise Linux 8 | sqlite-0:3.26.0-4.el8_1 | Fixed | RHSA-2020:0273 |
| Red Hat Enterprise Linux 8 | sqlite-0:3.26.0-4.el8_1 | Fixed | RHSA-2020:0273 |
| Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions | sqlite-0:3.26.0-4.el8_0 | Fixed | RHSA-2020:0229 |
| Red Hat Enterprise Linux 5 | sqlite | Not affected | n/a |
| Red Hat Enterprise Linux 6 | sqlite | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (24)
- http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00032.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00036.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4238 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0227 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0229 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0273 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0451 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0463 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0476 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-13734 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1781980 Issue Tracking
- https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html x_refsource_MISCVendor Advisory
- https://crbug.com/1025466 x_refsource_MISCPermissions RequiredVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-5151 Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2Z5M4FPUMDNX2LDPHJKN5ZV5GIS2AKNU/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N5CIQCVS6E3ULJCNU7YJXJPO2BLQZDTK/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2019-13734
- https://seclists.org/bugtraq/2020/Jan/27 mailing-listx_refsource_BUGTRAQMailing ListThird Party Advisory
- https://security.gentoo.org/glsa/202003-08 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://usn.ubuntu.com/4298-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4298-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-13734
- https://www.debian.org/security/2020/dsa-4606 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.html x_refsource_MISCPatchThird Party Advisory
Change history (0)
No recorded changes yet.