Back

HIGH

sqlite: heap-based buffer over-read in function fts5HashEntrySort in sqlite3.c

Published Mar 22, 2019

Description

In SQLite 3.27.2, running fts5 prefix queries inside a transaction could trigger a heap-based buffer over-read in fts5HashEntrySort in sqlite3.c, which may lead to an information leak. This is related to ext/fts5/fts5_hash.c.

Affected products

Remediation

Red Hat statement

This vulnerability is rated as low severity because it allows an attacker to obtain information through a heap-based buffer over-read, it could lead to data leakage, it does not pose an immediate risk to system integrity or availability. This issue did not affect the versions of sqlite as shipped with Red Hat Enterprise Linux 6 and 7 as they did not include support for fts5.

Metrics

References (17)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 22, 2019
Updated Aug 4, 2024
Reserved Mar 22, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Mar 18, 2019