cbcvebase.
CVE-2015-3415
published 2015-04-24

CVE-2015-3415: The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly implement comparison operators, which allows context-dependent attackers to…

high7.5CVSS 3.1
AVNACLAuNCPIPAP
The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly implement comparison operators, which allows context-dependent attackers to cause a denial of service (invalid free operation) or possibly have unspecified other impact via a crafted CHECK clause, as demonstrated by CHECK(0&O>O) in a CREATE TABLE statement.

Affected

21 ranges
VendorProductVersion rangeFixed in
appleios_9
appleitunes
appleitunes_12.6_for_windows
applemac_os_x
appleos_x_el_capitan_v10.11
applewatchos
applewatchos_2
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiansqlite3< sqlite3 3.8.9-1 (bookworm)sqlite3 3.8.9-1 (bookworm)
ghostsqlite3>= 0 < 3.8.9-13.8.9-1
ghostsqlite3>= 0 < 3.8.9-13.8.9-1
ghostsqlite3>= 0 < 3.8.9-13.8.9-1
ghostsqlite3>= 0 < 3.8.9-13.8.9-1
ghostsqlite3>= 0 < 3.8.2-1ubuntu2.13.8.2-1ubuntu2.1
phpphp>= 5.4.0 < 5.4.425.4.42
phpphp>= 5.5.0 < 5.5.265.5.26
phpphp>= 5.6.0 < 5.6.105.6.10
sqlitesqlite<= 3.8.8.3

CVSS provenance

nvd7.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH