Back

HIGH

sqlite: allows a crash if a sub-select uses both DISTINCT and window functions and also has certain ORDER BY usage

Published Nov 25, 2019

Description

sqlite3Select in select.c in SQLite 3.30.1 allows a crash if a sub-select uses both DISTINCT and window functions, and also has certain ORDER BY usage.

Affected products

Remediation

Red Hat statement

This flaw has been rated as having a security impact of Low. The versions of `sqlite` as shipped with Red Hat Enterprise Linux are compiled without SQLITE_DEBUG, so it's not possible to reproduce the crash. The invalid Mem object may still lead to undefined behaviors, though no notable defects have been observed.

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 25, 2019
Updated Aug 5, 2024
Reserved Nov 25, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Nov 22, 2019
ENISA EUVD
Assigner mitre
Published Nov 25, 2019
Updated Aug 5, 2024
Exploited since n/a
EUVD-2019-8870