CVE-2015-3414
published 2015-04-24CVE-2015-3414: SQLite before 3.8.9 does not properly implement the dequoting of collation-sequence names, which allows context-dependent attackers to cause a denial of…
PriorityP433high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
4.85%
91.0th percentile
SQLite before 3.8.9 does not properly implement the dequoting of collation-sequence names, which allows context-dependent attackers to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other impact via a crafted COLLATE clause, as demonstrated by COLLATE"""""""" at the end of a SELECT statement.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_9 | — | — |
| apple | itunes | — | — |
| apple | itunes_12.6_for_windows | — | — |
| apple | mac_os_x | — | — |
| apple | os_x_el_capitan_v10.11 | — | — |
| apple | watchos | — | — |
| apple | watchos_2 | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | sqlite3 | < sqlite3 3.8.9-1 (bookworm) | sqlite3 3.8.9-1 (bookworm) |
| ghost | sqlite3 | >= 0 < 3.8.9-1 | 3.8.9-1 |
| ghost | sqlite3 | >= 0 < 3.8.9-1 | 3.8.9-1 |
| ghost | sqlite3 | >= 0 < 3.8.9-1 | 3.8.9-1 |
| ghost | sqlite3 | >= 0 < 3.8.9-1 | 3.8.9-1 |
| ghost | sqlite3 | >= 0 < 3.8.2-1ubuntu2.1 | 3.8.2-1ubuntu2.1 |
| php | php | >= 5.4.0 < 5.4.42 | 5.4.42 |
| php | php | >= 5.5.0 < 5.5.26 | 5.5.26 |
| php | php | >= 5.6.0 < 5.6.10 | 5.6.10 |
| sqlite | sqlite | <= 3.8.8.3 | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2015-3414: iTunes 12.6
vendor_apple·2017-03-21·CVSS 7.5
CVE-2015-3414 [HIGH] CVE-2015-3414: iTunes 12.6
Apple Security Update: About the security content of iTunes 12.6
Product: iTunes
Version: 12.6
CVE: CVE-2015-3414
Component: CVE-2015-3414
Apple
CVE-2015-3414: iTunes 12.6 for Windows
vendor_apple·2017-03-21·CVSS 7.5
CVE-2015-3414 [HIGH] CVE-2015-3414: iTunes 12.6 for Windows
Apple Security Update: About the security content of iTunes 12.6 for Windows
Product: iTunes 12.6 for Windows
CVE: CVE-2015-3414
Component: CVE-2015-3414
Ubuntu
SQLite vulnerabilities
vendor_ubuntu·2015-07-30·CVSS 5.0
CVE-2013-7443 [MEDIUM] SQLite vulnerabilities
Title: SQLite vulnerabilities
Summary: SQLite could be made to crash or run programs if it processed specially
crafted queries.
It was discovered that SQLite incorrectly handled skip-scan optimization.
An attacker could use this issue to cause applications using SQLite to
crash, resulting in a denial of service, or possibly execute arbitrary
code. This issue only affected Ubuntu 14.04 LTS. (CVE-2013-7443)
Michal Zalewski discovered that SQLite incorrectly handled dequoting of
collation-sequence names. An attacker could use this issue to cause
applications using SQLite to crash, resulting in a denial of service, or
possibly execute arbitrary code. This issue only affected Ubuntu 14.04 LTS
and Ubuntu 15.04. (CVE-2015-3414)
Michal Zalewski discovered that SQLite incorrectly implemented co
Red Hat
sqlite: use of uninitialized memory when parsing collation sequences in src/where.c
vendor_redhat·2015-03-31·CVSS 7.5
CVE-2015-3414 [HIGH] CWE-456 sqlite: use of uninitialized memory when parsing collation sequences in src/where.c
sqlite: use of uninitialized memory when parsing collation sequences in src/where.c
SQLite before 3.8.9 does not properly implement the dequoting of collation-sequence names, which allows context-dependent attackers to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other impact via a crafted COLLATE clause, as demonstrated by COLLATE"""""""" at the end of a SELECT statement.
A flaw was found in the way SQLite handled dequoting of collation-sequence names. A local attacker could submit a specially crafted COLLATE statement that would crash the SQLite process, or have other unspecified impacts.
Package: sqlite (Red Hat Enterprise Linux 5) - Not affected
Package: sqlite (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2015-3414: sqlite3 - SQLite before 3.8.9 does not properly implement the dequoting of collation-seque...
vendor_debian·2015·CVSS 7.5
CVE-2015-3414 [HIGH] CVE-2015-3414: sqlite3 - SQLite before 3.8.9 does not properly implement the dequoting of collation-seque...
SQLite before 3.8.9 does not properly implement the dequoting of collation-sequence names, which allows context-dependent attackers to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other impact via a crafted COLLATE clause, as demonstrated by COLLATE"""""""" at the end of a SELECT statement.
Scope: local
bookworm: resolved (fixed in 3.8.9-1)
bullseye: resolved (fixed in 3.8.9-1)
forky: resolved (fixed in 3.8.9-1)
sid: resolved (fixed in 3.8.9-1)
trixie: resolved (fixed in 3.8.9-1)
Apple
CVE-2015-3414: OS X El Capitan v10.11
vendor_apple·CVSS 7.5
CVE-2015-3414 [HIGH] CVE-2015-3414: OS X El Capitan v10.11
Apple Security Update: About the security content of OS X El Capitan v10.11
Product: OS X El Capitan v10.11
CVE: CVE-2015-3414
Component: CVE-2015-3414
Apple
CVE-2015-3414: watchOS 2
vendor_apple·CVSS 7.5
CVE-2015-3414 [HIGH] CVE-2015-3414: watchOS 2
Apple Security Update: About the security content of watchOS 2
Product: watchOS 2
CVE: CVE-2015-3414
Component: CVE-2015-3414
Apple
CVE-2015-3414: iOS 9
vendor_apple·CVSS 7.5
CVE-2015-3414 [HIGH] CVE-2015-3414: iOS 9
Apple Security Update: About the security content of iOS 9
Product: iOS 9
CVE: CVE-2015-3414
Component: CVE-2015-3414
GHSA
GHSA-9qxq-827h-4w5v: SQLite before 3
ghsa_unreviewed·2022-05-14
CVE-2015-3414 [HIGH] CWE-20 GHSA-9qxq-827h-4w5v: SQLite before 3
SQLite before 3.8.9 does not properly implement the dequoting of collation-sequence names, which allows context-dependent attackers to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other impact via a crafted COLLATE clause, as demonstrated by COLLATE"""""""" at the end of a SELECT statement.
OSV
sqlite3 vulnerabilities
osv·2015-07-30·CVSS 5.0
CVE-2013-7443 [MEDIUM] sqlite3 vulnerabilities
sqlite3 vulnerabilities
It was discovered that SQLite incorrectly handled skip-scan optimization.
An attacker could use this issue to cause applications using SQLite to
crash, resulting in a denial of service, or possibly execute arbitrary
code. This issue only affected Ubuntu 14.04 LTS. (CVE-2013-7443)
Michal Zalewski discovered that SQLite incorrectly handled dequoting of
collation-sequence names. An attacker could use this issue to cause
applications using SQLite to crash, resulting in a denial of service, or
possibly execute arbitrary code. This issue only affected Ubuntu 14.04 LTS
and Ubuntu 15.04. (CVE-2015-3414)
Michal Zalewski discovered that SQLite incorrectly implemented comparison
operators. An attacker could use this issue to cause applications using
SQLite to crash, resulti
OSV
CVE-2015-3414: SQLite before 3
osv·2015-04-24·CVSS 7.5
CVE-2015-3414 [HIGH] CVE-2015-3414: SQLite before 3
SQLite before 3.8.9 does not properly implement the dequoting of collation-sequence names, which allows context-dependent attackers to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other impact via a crafted COLLATE clause, as demonstrated by COLLATE"""""""" at the end of a SELECT statement.
No detection rules found.
No public exploits indexed.
arXiv
UniBOM -- A Unified SBOM Analysis and Visualisation Tool for IoT Systems and Beyond
arxiv_fulltext·2025-11-27
UniBOM -- A Unified SBOM Analysis and Visualisation Tool for IoT Systems and Beyond
UniBOM – A Unified SBOM Analysis and Visualisation Tool for IoT Systems and Beyond
Vadim Safronov
Equal contribution.
[email protected]
University of Oxford
Oxford
United Kingdom
Ionut Bostan
[1]
[email protected]
NquiringMinds
Southampton
United Kingdom
Nicholas Allott
[email protected]
NquiringMinds
Southampton
United Kingdom
Andrew Martin
[email protected]
University of Oxford
Oxford
United Kingdom
Safronov et al.
## Abstract
Modern networked systems rely on complex software stacks, which often conceal vulnerabilities arising from intricate interdependencies. A Software Bill of Materials (SBOM) is effective for identifying dependencies and mitigating security risks. However, existing SBOM solutions lack precision, particularly in binary analysis a
arXiv
Talos: Neutralizing Vulnerabilities with Security Workarounds for Rapid Response
arxiv_fulltext·2017-11-02
Talos: Neutralizing Vulnerabilities with Security Workarounds for Rapid Response
Talos: Neutralizing Vulnerabilities with Security Workarounds for Rapid Response
Zhen Huang0.25in
Mariana D'Angelo0.25in
Dhaval Miyani0.25in
David Lie
University of Toronto
\z.huang,mariana.dangelo,dhaval.miyani\@mail.utoronto.ca,[email protected]
## Abstract
There is often a considerable delay between the discovery of a vulnerability and the issue of a patch. One way to mitigate this window of vulnerability is to use a configuration workaround, which prevents the vulnerable code from being executed at the cost of some lost functionality -- but only if one is available. Since application configurations are not specifically designed to mitigate software vulnerabilities, we find that they only cover 25.2% of vulnerabilities.
To minimize patch delay vulnerabilities and address the lim
Bugzilla
CVE-2015-3414 sqlite: use of uninitialized memory when parsing collation sequences in src/where.c
bugzilla·2015-04-16·CVSS 7.5
CVE-2015-3414 [HIGH] CVE-2015-3414 sqlite: use of uninitialized memory when parsing collation sequences in src/where.c
CVE-2015-3414 sqlite: use of uninitialized memory when parsing collation sequences in src/where.c
It was reported that SQLite was was using uninitialized memory when parsing collation sequences.
This issue was fixed by following upstream commit:
https://www.sqlite.org/src/info/eddc05e7bb31fae7
More information about this issue can be found in the links below:
http://www.securityfocus.com/archive/1/535269
http://lcamtuf.blogspot.fr/2015/04/finding-bugs-in-sqlite-easy-way.html
Discussion:
The issue is fixed in the latest upstream release, which is currently in updates-testing for F20 and newer.
---
Created sqlite tracking bugs for this issue:
Affects: fedora-all [bug 1212360]
---
spatialite-tools-4.2.0-10.fc21, sqlite-3.8.9-1.fc21 has been pushed to the Fedora 21 stable repository.
http://lists.apple.com/archives/security-announce/2015/Sep/msg00005.htmlhttp://lists.apple.com/archives/security-announce/2015/Sep/msg00008.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1635.htmlhttp://seclists.org/fulldisclosure/2015/Apr/31http://www.debian.org/security/2015/dsa-3252http://www.mandriva.com/security/advisories?name=MDVSA-2015:217http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/74228http://www.securitytracker.com/id/1033703http://www.ubuntu.com/usn/USN-2698-1https://security.gentoo.org/glsa/201507-05https://support.apple.com/HT205213https://support.apple.com/HT205267https://www.sqlite.org/src/info/eddc05e7bb31fae74daa86e0504a3478b99fa0f2http://lists.apple.com/archives/security-announce/2015/Sep/msg00005.htmlhttp://lists.apple.com/archives/security-announce/2015/Sep/msg00008.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1635.htmlhttp://seclists.org/fulldisclosure/2015/Apr/31http://www.debian.org/security/2015/dsa-3252http://www.mandriva.com/security/advisories?name=MDVSA-2015:217http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/74228http://www.securitytracker.com/id/1033703http://www.ubuntu.com/usn/USN-2698-1https://security.gentoo.org/glsa/201507-05https://support.apple.com/HT205213https://support.apple.com/HT205267https://www.sqlite.org/src/info/eddc05e7bb31fae74daa86e0504a3478b99fa0f2
2015-04-24
Published