sqlite: invalid pointer dereference in exprListAppendList in window.c
Published Dec 18, 2019
7.5
HIGHCVSS 3.1
EPSS 6.94%
Description
exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values in ORDER BY clauses of window definitions are mishandled.
Affected products
No data.
Configuration 2
- n/a
Configuration 3
- 9.0
- 10.0
Configuration 4
- n/a
Running on/with
- 12.0
Configuration 5
- 6.0
- 6.0
- 6.0
Configuration 6
- 15.0
- 15.1
Configuration 7
- ≤ 8.0.19
Configuration 8
- < 1.0.1.1
No data.
Red Hat Enterprise Linux 6 Supplementary
chromium-browser-0:80.0.3987.87-1.el6_10
Fixed · RHSA-2020:0514
Red Hat Enterprise Linux 5
sqlite
Out of support scope
Red Hat Enterprise Linux 6
sqlite
Out of support scope
Red Hat Enterprise Linux 7
sqlite
Will not fix
Red Hat Enterprise Linux 8
sqlite
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 Supplementary | chromium-browser-0:80.0.3987.87-1.el6_10 | Fixed | RHSA-2020:0514 |
| Red Hat Enterprise Linux 5 | sqlite | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | sqlite | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | sqlite | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | sqlite | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (15)
- http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00010.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00015.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00025.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0514 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-19880 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1787032 Issue Tracking
- https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf x_refsource_CONFIRMPatchThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-9473 Advisory
- https://github.com/sqlite/sqlite/commit/75e95e1fcd52d3ec8282edb75ac8cd0814095d54 x_refsource_MISCPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-19880
- https://security.netapp.com/advisory/ntap-20200114-0001/ x_refsource_CONFIRMThird Party Advisory
- https://usn.ubuntu.com/4298-1/ vendor-advisoryx_refsource_UBUNTUBroken Link
- https://www.cve.org/CVERecord?id=CVE-2019-19880
- https://www.debian.org/security/2020/dsa-4638 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2020.html x_refsource_MISCPatchThird Party Advisory
Change history (0)
No recorded changes yet.