cbcvebase.
CVE-2015-3414
published 2015-04-24

CVE-2015-3414: SQLite before 3.8.9 does not properly implement the dequoting of collation-sequence names, which allows context-dependent attackers to cause a denial of…

high7.5CVSS 3.1
AVNACLAuNCPIPAP
SQLite before 3.8.9 does not properly implement the dequoting of collation-sequence names, which allows context-dependent attackers to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other impact via a crafted COLLATE clause, as demonstrated by COLLATE"""""""" at the end of a SELECT statement.

Affected

21 ranges
VendorProductVersion rangeFixed in
appleios_9
appleitunes
appleitunes_12.6_for_windows
applemac_os_x
appleos_x_el_capitan_v10.11
applewatchos
applewatchos_2
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiansqlite3< sqlite3 3.8.9-1 (bookworm)sqlite3 3.8.9-1 (bookworm)
ghostsqlite3>= 0 < 3.8.9-13.8.9-1
ghostsqlite3>= 0 < 3.8.9-13.8.9-1
ghostsqlite3>= 0 < 3.8.9-13.8.9-1
ghostsqlite3>= 0 < 3.8.9-13.8.9-1
ghostsqlite3>= 0 < 3.8.2-1ubuntu2.13.8.2-1ubuntu2.1
phpphp>= 5.4.0 < 5.4.425.4.42
phpphp>= 5.5.0 < 5.5.265.5.26
phpphp>= 5.6.0 < 5.6.105.6.10
sqlitesqlite<= 3.8.8.3

CVSS provenance

nvd7.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH