CVE-2015-3415
published 2015-04-24CVE-2015-3415: The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly implement comparison operators, which allows context-dependent attackers to…
PriorityP335high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
4.85%
91.1th percentile
The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly implement comparison operators, which allows context-dependent attackers to cause a denial of service (invalid free operation) or possibly have unspecified other impact via a crafted CHECK clause, as demonstrated by CHECK(0&O>O) in a CREATE TABLE statement.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_9 | — | — |
| apple | itunes | — | — |
| apple | itunes_12.6_for_windows | — | — |
| apple | mac_os_x | — | — |
| apple | os_x_el_capitan_v10.11 | — | — |
| apple | watchos | — | — |
| apple | watchos_2 | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | sqlite3 | < sqlite3 3.8.9-1 (bookworm) | sqlite3 3.8.9-1 (bookworm) |
| ghost | sqlite3 | >= 0 < 3.8.9-1 | 3.8.9-1 |
| ghost | sqlite3 | >= 0 < 3.8.9-1 | 3.8.9-1 |
| ghost | sqlite3 | >= 0 < 3.8.9-1 | 3.8.9-1 |
| ghost | sqlite3 | >= 0 < 3.8.9-1 | 3.8.9-1 |
| ghost | sqlite3 | >= 0 < 3.8.2-1ubuntu2.1 | 3.8.2-1ubuntu2.1 |
| php | php | >= 5.4.0 < 5.4.42 | 5.4.42 |
| php | php | >= 5.5.0 < 5.5.26 | 5.5.26 |
| php | php | >= 5.6.0 < 5.6.10 | 5.6.10 |
| sqlite | sqlite | <= 3.8.8.3 | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2015-3415: iTunes 12.6 for Windows
vendor_apple·2017-03-21·CVSS 7.5
CVE-2015-3415 [HIGH] CVE-2015-3415: iTunes 12.6 for Windows
Apple Security Update: About the security content of iTunes 12.6 for Windows
Product: iTunes 12.6 for Windows
CVE: CVE-2015-3415
Component: CVE-2015-3415
Apple
CVE-2015-3415: iTunes 12.6
vendor_apple·2017-03-21·CVSS 7.5
CVE-2015-3415 [HIGH] CVE-2015-3415: iTunes 12.6
Apple Security Update: About the security content of iTunes 12.6
Product: iTunes
Version: 12.6
CVE: CVE-2015-3415
Component: CVE-2015-3415
Ubuntu
SQLite vulnerabilities
vendor_ubuntu·2015-07-30·CVSS 5.0
CVE-2013-7443 [MEDIUM] SQLite vulnerabilities
Title: SQLite vulnerabilities
Summary: SQLite could be made to crash or run programs if it processed specially
crafted queries.
It was discovered that SQLite incorrectly handled skip-scan optimization.
An attacker could use this issue to cause applications using SQLite to
crash, resulting in a denial of service, or possibly execute arbitrary
code. This issue only affected Ubuntu 14.04 LTS. (CVE-2013-7443)
Michal Zalewski discovered that SQLite incorrectly handled dequoting of
collation-sequence names. An attacker could use this issue to cause
applications using SQLite to crash, resulting in a denial of service, or
possibly execute arbitrary code. This issue only affected Ubuntu 14.04 LTS
and Ubuntu 15.04. (CVE-2015-3414)
Michal Zalewski discovered that SQLite incorrectly implemented co
Red Hat
sqlite: invalid free() in src/vdbe.c
vendor_redhat·2015-03-31·CVSS 7.5
CVE-2015-3415 [HIGH] sqlite: invalid free() in src/vdbe.c
sqlite: invalid free() in src/vdbe.c
The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly implement comparison operators, which allows context-dependent attackers to cause a denial of service (invalid free operation) or possibly have unspecified other impact via a crafted CHECK clause, as demonstrated by CHECK(0&O>O) in a CREATE TABLE statement.
It was found that SQLite's sqlite3VdbeExec() function did not properly implement comparison operators. A local attacker could submit a specially crafted CHECK statement that would crash the SQLite process, or have other unspecified impacts.
Package: sqlite (Red Hat Enterprise Linux 5) - Not affected
Package: sqlite (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2015-3415: sqlite3 - The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly ...
vendor_debian·2015·CVSS 7.5
CVE-2015-3415 [HIGH] CVE-2015-3415: sqlite3 - The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly ...
The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly implement comparison operators, which allows context-dependent attackers to cause a denial of service (invalid free operation) or possibly have unspecified other impact via a crafted CHECK clause, as demonstrated by CHECK(0&O>O) in a CREATE TABLE statement.
Scope: local
bookworm: resolved (fixed in 3.8.9-1)
bullseye: resolved (fixed in 3.8.9-1)
forky: resolved (fixed in 3.8.9-1)
sid: resolved (fixed in 3.8.9-1)
trixie: resolved (fixed in 3.8.9-1)
Apple
CVE-2015-3415: watchOS 2
vendor_apple·CVSS 7.5
CVE-2015-3415 [HIGH] CVE-2015-3415: watchOS 2
Apple Security Update: About the security content of watchOS 2
Product: watchOS 2
CVE: CVE-2015-3415
Component: CVE-2015-3415
Apple
CVE-2015-3415: iOS 9
vendor_apple·CVSS 7.5
CVE-2015-3415 [HIGH] CVE-2015-3415: iOS 9
Apple Security Update: About the security content of iOS 9
Product: iOS 9
CVE: CVE-2015-3415
Component: CVE-2015-3415
Apple
CVE-2015-3415: OS X El Capitan v10.11
vendor_apple·CVSS 7.5
CVE-2015-3415 [HIGH] CVE-2015-3415: OS X El Capitan v10.11
Apple Security Update: About the security content of OS X El Capitan v10.11
Product: OS X El Capitan v10.11
CVE: CVE-2015-3415
Component: CVE-2015-3415
GHSA
GHSA-p88q-qx6q-mhv3: The sqlite3VdbeExec function in vdbe
ghsa_unreviewed·2022-05-14
CVE-2015-3415 [HIGH] CWE-20 GHSA-p88q-qx6q-mhv3: The sqlite3VdbeExec function in vdbe
The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly implement comparison operators, which allows context-dependent attackers to cause a denial of service (invalid free operation) or possibly have unspecified other impact via a crafted CHECK clause, as demonstrated by CHECK(0&O>O) in a CREATE TABLE statement.
OSV
sqlite3 vulnerabilities
osv·2015-07-30·CVSS 5.0
CVE-2013-7443 [MEDIUM] sqlite3 vulnerabilities
sqlite3 vulnerabilities
It was discovered that SQLite incorrectly handled skip-scan optimization.
An attacker could use this issue to cause applications using SQLite to
crash, resulting in a denial of service, or possibly execute arbitrary
code. This issue only affected Ubuntu 14.04 LTS. (CVE-2013-7443)
Michal Zalewski discovered that SQLite incorrectly handled dequoting of
collation-sequence names. An attacker could use this issue to cause
applications using SQLite to crash, resulting in a denial of service, or
possibly execute arbitrary code. This issue only affected Ubuntu 14.04 LTS
and Ubuntu 15.04. (CVE-2015-3414)
Michal Zalewski discovered that SQLite incorrectly implemented comparison
operators. An attacker could use this issue to cause applications using
SQLite to crash, resulti
OSV
CVE-2015-3415: The sqlite3VdbeExec function in vdbe
osv·2015-04-24·CVSS 7.5
CVE-2015-3415 [HIGH] CVE-2015-3415: The sqlite3VdbeExec function in vdbe
The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly implement comparison operators, which allows context-dependent attackers to cause a denial of service (invalid free operation) or possibly have unspecified other impact via a crafted CHECK clause, as demonstrated by CHECK(0&O>O) in a CREATE TABLE statement.
No detection rules found.
No public exploits indexed.
http://lists.apple.com/archives/security-announce/2015/Sep/msg00005.htmlhttp://lists.apple.com/archives/security-announce/2015/Sep/msg00008.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1635.htmlhttp://seclists.org/fulldisclosure/2015/Apr/31http://www.debian.org/security/2015/dsa-3252http://www.mandriva.com/security/advisories?name=MDVSA-2015:217http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/74228http://www.securitytracker.com/id/1033703http://www.ubuntu.com/usn/USN-2698-1https://security.gentoo.org/glsa/201507-05https://support.apple.com/HT205213https://support.apple.com/HT205267https://www.sqlite.org/src/info/02e3c88fbf6abdcf3975fb0fb71972b0ab30da30http://lists.apple.com/archives/security-announce/2015/Sep/msg00005.htmlhttp://lists.apple.com/archives/security-announce/2015/Sep/msg00008.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1635.htmlhttp://seclists.org/fulldisclosure/2015/Apr/31http://www.debian.org/security/2015/dsa-3252http://www.mandriva.com/security/advisories?name=MDVSA-2015:217http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/74228http://www.securitytracker.com/id/1033703http://www.ubuntu.com/usn/USN-2698-1https://security.gentoo.org/glsa/201507-05https://support.apple.com/HT205213https://support.apple.com/HT205267https://www.sqlite.org/src/info/02e3c88fbf6abdcf3975fb0fb71972b0ab30da30
2015-04-24
Published