MEDIUM
symisc UnQLite unqlite.c jx9MemObjStore heap-based overflow
Published Apr 18, 2025
4.8
MEDIUMCVSS 4.0
EPSS 0.22%
Description
A vulnerability classified as critical was found in symisc UnQLite up to 957c377cb691a4f617db9aba5cc46d90425071e2. This vulnerability affects the function jx9MemObjStore of the file /data/src/benchmarks/unqlite/unqlite.c. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.
Affected products
-
- Version StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-11879 Advisory
- https://github.com/symisc/unqlite/issues/173 issue-tracking
- https://github.com/user-attachments/files/19652580/unqlite-reproduce-heap-overflow.zip exploit
- https://vuldb.com/?ctiid.305614 signaturepermissions-required
- https://vuldb.com/?id.305614 vdb-entrytechnical-description
- https://vuldb.com/?submit.554574 third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-11879 | Advisory | |
| https://github.com/symisc/unqlite/issues/173 | issue-tracking | |
| https://github.com/user-attachments/files/19652580/unqlite-reproduce-heap-overflow.zip | exploit | |
| https://vuldb.com/?ctiid.305614 | signaturepermissions-required | |
| https://vuldb.com/?id.305614 | vdb-entrytechnical-description | |
| https://vuldb.com/?submit.554574 | third-party-advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Apr 18, 2025
Updated Apr 18, 2025
Reserved Apr 18, 2025
Link CVE-2025-3791
CISA Vulnrichment
Updated Apr 18, 2025
ENISA EUVD
EUVD-2025-11879 Assigner VulDB
Published Apr 18, 2025
Updated Apr 18, 2025
Exploited since n/a
Link EUVD-2025-11879