sqlite: crafted SQL query allows a malicious user to obtain sensitive information
Published Feb 14, 2022
4.3
MEDIUMCVSS 3.1
EPSS 1.61%
Description
A Memory Leak vulnerability exists in SQLite Project SQLite3 3.35.1 and 3.37.0 via maliciously crafted SQL Queries (made via editing the Database File), it is possible to query a record, and leak subsequent bytes of memory that extend beyond the record, which could let a malicious user obtain sensitive information. NOTE: The developer disputes this as a vulnerability stating that If you give SQLite a corrupted database file and submit a query against the database, it might read parts of the database that you did not intend or expect.
Affected products
No data.
No data.
Red Hat Enterprise Linux 6
sqlite
Out of support scope
Red Hat Enterprise Linux 7
sqlite
Out of support scope
Red Hat Enterprise Linux 8
mingw-sqlite
Fix deferred
Red Hat Enterprise Linux 8
sqlite
Not affected
Red Hat Enterprise Linux 9
sqlite
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | sqlite | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | sqlite | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | mingw-sqlite | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | sqlite | Not affected | n/a |
| Red Hat Enterprise Linux 9 | sqlite | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (10)
- https://access.redhat.com/security/cve/CVE-2021-45346 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2054793 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-32119 Advisory
- https://github.com/guyinatuxedo/sqlite3_record_leaking ExploitThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-45346
- https://security.netapp.com/advisory/ntap-20220303-0001/ Third Party Advisory
- https://sqlite.org/forum/forumpost/056d557c2f8c452ed5 Vendor Advisory
- https://sqlite.org/forum/forumpost/53de8864ba114bf6 Vendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2021-45346
- https://www.sqlite.org/cves.html#status_of_recent_sqlite_cves Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2021-45346 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2054793 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-32119 | Advisory | |
| https://github.com/guyinatuxedo/sqlite3_record_leaking | ExploitThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2021-45346 | ||
| https://security.netapp.com/advisory/ntap-20220303-0001/ | Third Party Advisory | |
| https://sqlite.org/forum/forumpost/056d557c2f8c452ed5 | Vendor Advisory | |
| https://sqlite.org/forum/forumpost/53de8864ba114bf6 | Vendor Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2021-45346 | ||
| https://www.sqlite.org/cves.html#status_of_recent_sqlite_cves | Vendor Advisory |
Change history (0)
No recorded changes yet.