CVE-2017-13685Improper Input Validation in Sqlite

Severity
5.5MEDIUMNVD
EPSS
0.4%
top 39.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 29
Latest updateMay 17

Description

The dump_callback function in SQLite 3.20.0 allows remote attackers to cause a denial of service (EXC_BAD_ACCESS and application crash) via a crafted file.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

Debianghost/sqlite3< 3.20.1-1+3
NVDsqlite/sqlite3.20.0

🔴Vulnerability Details

3
GHSA
GHSA-69wm-j7rv-57pp: The dump_callback function in SQLite 32022-05-17
OSV
CVE-2017-13685: The dump_callback function in SQLite 32017-08-29
CVEList
CVE-2017-13685: The dump_callback function in SQLite 32017-08-29

📋Vendor Advisories

4
Ubuntu
SQLite vulnerabilities2019-06-19
Ubuntu
SQLite vulnerabilities2019-06-19
Red Hat
sqlite: Local DoS via dump_callback function2017-08-28
Debian
CVE-2017-13685: sqlite3 - The dump_callback function in SQLite 3.20.0 allows remote attackers to cause a d...2017

💬Community

5
Bugzilla
CVE-2017-13685 CVE-2017-15286 sqlite: various flaws [fedora-all]2017-09-06
Bugzilla
CVE-2017-13685 sqlite: Local DoS via dump_callback function2017-09-06
Bugzilla
CVE-2017-13685 CVE-2017-15286 mingw-sqlite: various flaws [fedora-all]2017-09-06
Bugzilla
CVE-2017-13685 CVE-2017-15286 mingw-sqlite: various flaws [epel-7]2017-09-06
Bugzilla
CVE-2017-9349 wireshark: DICOM dissector infinite loop (wnpa-sec-2017-27)2017-06-02
CVE-2017-13685 — Improper Input Validation in Sqlite | cvebase