cbcvebase.
CVE-2018-20505
published 2019-04-03

CVE-2018-20505: SQLite 3.25.2, when queries are run on a table with a malformed PRIMARY KEY, allows remote attackers to cause a denial of service (application crash) by…

PriorityP341high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
6.95%
93.4th percentile
SQLite 3.25.2, when queries are run on a table with a malformed PRIMARY KEY, allows remote attackers to cause a denial of service (application crash) by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases).

Affected

25 ranges
VendorProductVersion rangeFixed in
appleicloud< 7.107.10
appleicloud_for_windows
appleios
appleiphone_os< 12.1.312.1.3
appleitunes< 12.9.312.9.3
appleitunes_12.9.3_for_windows
applemac_os_x< 10.14.210.14.2
applemacos_mojave_10.14.3_security_update_2019-001_high_sierra_security_update_2019-0
appletvos
applewatchos< 5.1.35.1.3
applewatchos
debiansqlite3< sqlite3 3.25.3-1 (bookworm)sqlite3 3.25.3-1 (bookworm)
ghostsqlite3>= 0 < 3.25.3-13.25.3-1
ghostsqlite3>= 0 < 3.25.3-13.25.3-1
ghostsqlite3>= 0 < 3.25.3-13.25.3-1
ghostsqlite3>= 0 < 3.25.3-13.25.3-1
ghostsqlite3>= 0 < 3.11.0-1ubuntu1.23.11.0-1ubuntu1.2
ghostsqlite3>= 0 < 3.22.0-1ubuntu0.13.22.0-1ubuntu0.1
msrcazl3_ceph_16.2.10-3_on_azure_linux_3.0
msrcazl3_ceph_18.2.1-1_on_azure_linux_3.0
msrcazl3_heimdal_7.8.0-3_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_ceph_16.2.10-7_on_cbl_mariner_2.0
sqlitesqlite<= 3.25.2

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.