CVE-2017-15286NULL Pointer Dereference in Sqlite

Severity
7.5HIGHNVD
EPSS
0.5%
top 35.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 12
Latest updateMay 17

Description

SQLite 3.20.1 has a NULL pointer dereference in tableColumnList in shell.c because it fails to consider certain cases where `sqlite3_step(pStmt)==SQLITE_ROW` is false and a data structure is never initialized.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

Debianghost/sqlite3< 3.20.1-2+3
NVDsqlite/sqlite3.20.1

🔴Vulnerability Details

3
GHSA
GHSA-cmxm-6c5m-r5c5: SQLite 32022-05-17
OSV
CVE-2017-15286: SQLite 32017-10-12
CVEList
CVE-2017-15286: SQLite 32017-10-12

📋Vendor Advisories

2
Red Hat
sqlite: NULL pointer dereference in tableColumnList2017-10-12
Debian
CVE-2017-15286: sqlite3 - SQLite 3.20.1 has a NULL pointer dereference in tableColumnList in shell.c becau...2017

💬Community

4
Bugzilla
CVE-2017-15286 sqlite: NULL pointer dereference in tableColumnList2017-11-07
Bugzilla
CVE-2017-13685 CVE-2017-15286 sqlite: various flaws [fedora-all]2017-09-06
Bugzilla
CVE-2017-13685 CVE-2017-15286 mingw-sqlite: various flaws [fedora-all]2017-09-06
Bugzilla
CVE-2017-13685 CVE-2017-15286 mingw-sqlite: various flaws [epel-7]2017-09-06
CVE-2017-15286 — NULL Pointer Dereference in Sqlite | cvebase