CVE-2018-20506
published 2019-04-03CVE-2018-20506: SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge"…
PriorityP355high8.1CVSS 3.0
AVNACHPRNUINSUCHIHAH
EPSS
7.56%
93.8th percentile
SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases). This is a different vulnerability than CVE-2018-20346.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | icloud | <= 7.10 | — |
| apple | icloud_for_windows | — | — |
| apple | ios | — | — |
| apple | iphone_os | < 12.1.3 | 12.1.3 |
| apple | itunes | <= 12.9.3 | — |
| apple | itunes_12.9.3_for_windows | — | — |
| apple | mac_os_x | < 10.14.3 | 10.14.3 |
| apple | macos_mojave_10.14.3_security_update_2019-001_high_sierra_security_update_2019-0 | — | — |
| apple | tvos | < 12.1.2 | 12.1.2 |
| apple | tvos | — | — |
| apple | watchos | < 5.1.3 | 5.1.3 |
| apple | watchos | — | — |
| debian | sqlite3 | < sqlite3 3.25.3-1 (bookworm) | sqlite3 3.25.3-1 (bookworm) |
| ghost | sqlite3 | >= 0 < 3.25.3-1 | 3.25.3-1 |
| ghost | sqlite3 | >= 0 < 3.25.3-1 | 3.25.3-1 |
| ghost | sqlite3 | >= 0 < 3.25.3-1 | 3.25.3-1 |
| ghost | sqlite3 | >= 0 < 3.25.3-1 | 3.25.3-1 |
| ghost | sqlite3 | >= 0 < 3.11.0-1ubuntu1.2 | 3.11.0-1ubuntu1.2 |
| ghost | sqlite3 | >= 0 < 3.22.0-1ubuntu0.1 | 3.22.0-1ubuntu0.1 |
| ghost | sqlite3 | >= 0 < 3.8.2-1ubuntu2.2+esm1 | 3.8.2-1ubuntu2.2+esm1 |
| msrc | azl3_ceph_16.2.10-3_on_azure_linux_3.0 | — | — |
| msrc | azl3_ceph_18.2.1-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_heimdal_7.8.0-3_on_azure_linux_3.0 | — | — |
| msrc | azl3_libdb_5.3.28-9_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
CVSS provenance
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.1HIGH
vendor_debian8.1HIGH
vendor_msrc8.1HIGH
vendor_redhat8.1HIGH
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
SQLite vulnerabilities
vendor_ubuntu·2019-06-19·CVSS 5.9
CVE-2016-6153 [MEDIUM] SQLite vulnerabilities
Title: SQLite vulnerabilities
Summary: Several security issues were fixed in SQLite.
USN-4019-1 fixed several vulnerabilities in sqlite3. This update provides
the corresponding update for Ubuntu 12.04 ESM and 14.04 ESM.
Original advisory details:
It was discovered that SQLite incorrectly handled certain SQL files.
An attacker could possibly use this issue to execute arbitrary code
or cause a denial of service. (CVE-2017-2518)
It was discovered that SQLite incorrectly handled certain queries.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2018-20346, CVE-2018-20506)
It was discovered that SQLite incorrectly handled certain inputs.
An attacker could possibly use this issue to access sensitive information.
(CVE-2019-8457)
It was discovered that SQLite incorre
Ubuntu
SQLite vulnerabilities
vendor_ubuntu·2019-06-19·CVSS 5.9
CVE-2016-6153 [MEDIUM] SQLite vulnerabilities
Title: SQLite vulnerabilities
Summary: Several security issues were fixed in SQLite.
It was discovered that SQLite incorrectly handled certain SQL files.
An attacker could possibly use this issue to execute arbitrary code
or cause a denial of service. This issue only affected Ubuntu 16.04
LTS. (CVE-2017-2518, CVE-2017-2520)
It was discovered that SQLite incorrectly handled certain queries.
An attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 18.04 LTS and Ubuntu 18.10. (CVE-2018-20505)
It was discovered that SQLite incorrectly handled certain queries.
An attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and
Ubuntu 18.10. (CVE-2018-20346, CVE-2018-20506)
It was di
Microsoft
SQLite before 3.25.3 when the FTS3 extension is enabled encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3
vendor_msrc·2019-04-09·CVSS 8.1
CVE-2018-20506 [HIGH] CWE-190 SQLite before 3.25.3 when the FTS3 extension is enabled encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3
SQLite before 3.25.3 when the FTS3 extension is enabled encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases). This is a different vulnerability than CVE-2018-20346.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed.
Apple
CVE-2018-20506: iTunes 12.9.3 for Windows
vendor_apple·2019-01-24·CVSS 8.1
CVE-2018-20506 [HIGH] CVE-2018-20506: iTunes 12.9.3 for Windows
Apple Security Update: About the security content of iTunes 12.9.3 for Windows
Product: iTunes 12.9.3 for Windows
CVE: CVE-2018-20506
Component: SQLite
Impact: A maliciously crafted SQL query may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved input validation.
Apple
CVE-2018-20506: iCloud for Windows 7.10
vendor_apple·2019-01-22·CVSS 8.1
CVE-2018-20506 [HIGH] CVE-2018-20506: iCloud for Windows 7.10
Apple Security Update: About the security content of iCloud for Windows 7.10
Product: iCloud for Windows
Version: 7.10
CVE: CVE-2018-20506
Component: SQLite
Impact: A maliciously crafted SQL query may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved input validation.
Apple
CVE-2018-20506: macOS Mojave 10.14.3, Security Update 2019-001 High Sierra, Security Update 2019-001 Sierra
vendor_apple·2019-01-22·CVSS 8.1
CVE-2018-20506 [HIGH] CVE-2018-20506: macOS Mojave 10.14.3, Security Update 2019-001 High Sierra, Security Update 2019-001 Sierra
Apple Security Update: About the security content of macOS Mojave 10.14.3, Security Update 2019-001 High Sierra, Security Update 2019-001 Sierra
Product: macOS Mojave 10.14.3, Security Update 2019-001 High Sierra, Security Update 2019-001 Sierra
CVE: CVE-2018-20506
Component: SQLite
Impact: A maliciously crafted SQL query may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved input validation.
Apple
CVE-2018-20506: iOS 12.1.3
vendor_apple·2019-01-22·CVSS 8.1
CVE-2018-20506 [HIGH] CVE-2018-20506: iOS 12.1.3
Apple Security Update: About the security content of iOS 12.1.3
Product: iOS
Version: 12.1.3
CVE: CVE-2018-20506
Component: SQLite
Impact: A maliciously crafted SQL query may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved input validation.
Apple
CVE-2018-20506: watchOS 5.1.3
vendor_apple·2019-01-22·CVSS 8.1
CVE-2018-20506 [HIGH] CVE-2018-20506: watchOS 5.1.3
Apple Security Update: About the security content of watchOS 5.1.3
Product: watchOS
Version: 5.1.3
CVE: CVE-2018-20506
Component: SQLite
Impact: A maliciously crafted SQL query may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved input validation.
Apple
CVE-2018-20506: tvOS 12.1.2
vendor_apple·2019-01-22·CVSS 8.1
CVE-2018-20506 [HIGH] CVE-2018-20506: tvOS 12.1.2
Apple Security Update: About the security content of tvOS 12.1.2
Product: tvOS
Version: 12.1.2
CVE: CVE-2018-20506
Component: SQLite
Impact: A maliciously crafted SQL query may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved input validation.
Red Hat
sqlite: Multiple flaws in sqlite which can be triggered via corrupted internal databases (Magellan)
vendor_redhat·2018-12-04·CVSS 8.1
CVE-2018-20506 [HIGH] sqlite: Multiple flaws in sqlite which can be triggered via corrupted internal databases (Magellan)
sqlite: Multiple flaws in sqlite which can be triggered via corrupted internal databases (Magellan)
SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases). This is a different vulnerability than CVE-2018-20346.
Multiple flaws were found in sqlite. An attacker having the ability to run arbitrary SQL commands could use this flaw to execute arbitrary code with the permission of the user running the sqlite application.
Statement: This flaw does not affect the versions of sqlite package
Debian
CVE-2018-20506: sqlite3 - SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer ...
vendor_debian·2018·CVSS 8.1
CVE-2018-20506 [HIGH] CVE-2018-20506: sqlite3 - SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer ...
SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases). This is a different vulnerability than CVE-2018-20346.
Scope: local
bookworm: resolved (fixed in 3.25.3-1)
bullseye: resolved (fixed in 3.25.3-1)
forky: resolved (fixed in 3.25.3-1)
sid: resolved (fixed in 3.25.3-1)
trixie: resolved (fixed in 3.25.3-1)
GHSA
GHSA-hfxx-8v8g-6rcx: SQLite before 3
ghsa_unreviewed·2022-05-13·CVSS 8.1
CVE-2018-20506 [HIGH] CWE-190 GHSA-hfxx-8v8g-6rcx: SQLite before 3
SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases). This is a different vulnerability than CVE-2018-20346.
OSV
sqlite3 vulnerabilities
osv·2019-06-19·CVSS 5.9
CVE-2017-2518 [MEDIUM] sqlite3 vulnerabilities
sqlite3 vulnerabilities
It was discovered that SQLite incorrectly handled certain SQL files.
An attacker could possibly use this issue to execute arbitrary code
or cause a denial of service. This issue only affected Ubuntu 16.04
LTS. (CVE-2017-2518, CVE-2017-2520)
It was discovered that SQLite incorrectly handled certain queries.
An attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 18.04 LTS and Ubuntu 18.10. (CVE-2018-20505)
It was discovered that SQLite incorrectly handled certain queries.
An attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and
Ubuntu 18.10. (CVE-2018-20346, CVE-2018-20506)
It was discovered that SQLite incorrectly handled certain inputs.
An at
OSV
sqlite3 vulnerabilities
osv·2019-06-19·CVSS 5.9
CVE-2017-2518 [MEDIUM] sqlite3 vulnerabilities
sqlite3 vulnerabilities
USN-4019-1 fixed several vulnerabilities in sqlite3. This update provides
the corresponding update for Ubuntu 12.04 ESM and 14.04 ESM.
Original advisory details:
It was discovered that SQLite incorrectly handled certain SQL files.
An attacker could possibly use this issue to execute arbitrary code
or cause a denial of service. (CVE-2017-2518)
It was discovered that SQLite incorrectly handled certain queries.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2018-20346, CVE-2018-20506)
It was discovered that SQLite incorrectly handled certain inputs.
An attacker could possibly use this issue to access sensitive information.
(CVE-2019-8457)
It was discovered that SQLite incorrectly handled certain inputs.
An attacker could possibly use th
OSV
CVE-2018-20506: SQLite before 3
osv·2019-04-03·CVSS 8.1
CVE-2018-20506 [HIGH] CVE-2018-20506: SQLite before 3
SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases). This is a different vulnerability than CVE-2018-20346.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00070.htmlhttp://seclists.org/fulldisclosure/2019/Jan/62http://seclists.org/fulldisclosure/2019/Jan/64http://seclists.org/fulldisclosure/2019/Jan/66http://seclists.org/fulldisclosure/2019/Jan/67http://seclists.org/fulldisclosure/2019/Jan/68http://seclists.org/fulldisclosure/2019/Jan/69http://www.securityfocus.com/bid/106698https://kc.mcafee.com/corporate/index?page=content&id=SB10365https://lists.debian.org/debian-lts-announce/2020/08/msg00037.htmlhttps://seclists.org/bugtraq/2019/Jan/28https://seclists.org/bugtraq/2019/Jan/29https://seclists.org/bugtraq/2019/Jan/31https://seclists.org/bugtraq/2019/Jan/32https://seclists.org/bugtraq/2019/Jan/33https://seclists.org/bugtraq/2019/Jan/39https://security.netapp.com/advisory/ntap-20190502-0004/https://sqlite.org/src/info/940f2adc8541a838https://support.apple.com/kb/HT209443https://support.apple.com/kb/HT209446https://support.apple.com/kb/HT209447https://support.apple.com/kb/HT209448https://support.apple.com/kb/HT209450https://support.apple.com/kb/HT209451https://usn.ubuntu.com/4019-1/https://usn.ubuntu.com/4019-2/https://www.oracle.com/security-alerts/cpuapr2020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00070.htmlhttp://seclists.org/fulldisclosure/2019/Jan/62http://seclists.org/fulldisclosure/2019/Jan/64http://seclists.org/fulldisclosure/2019/Jan/66http://seclists.org/fulldisclosure/2019/Jan/67http://seclists.org/fulldisclosure/2019/Jan/68http://seclists.org/fulldisclosure/2019/Jan/69http://www.securityfocus.com/bid/106698https://kc.mcafee.com/corporate/index?page=content&id=SB10365https://lists.debian.org/debian-lts-announce/2020/08/msg00037.htmlhttps://seclists.org/bugtraq/2019/Jan/28https://seclists.org/bugtraq/2019/Jan/29https://seclists.org/bugtraq/2019/Jan/31https://seclists.org/bugtraq/2019/Jan/32https://seclists.org/bugtraq/2019/Jan/33https://seclists.org/bugtraq/2019/Jan/39https://security.netapp.com/advisory/ntap-20190502-0004/https://sqlite.org/src/info/940f2adc8541a838https://support.apple.com/kb/HT209443https://support.apple.com/kb/HT209446https://support.apple.com/kb/HT209447https://support.apple.com/kb/HT209448https://support.apple.com/kb/HT209450https://support.apple.com/kb/HT209451https://usn.ubuntu.com/4019-1/https://usn.ubuntu.com/4019-2/https://www.oracle.com/security-alerts/cpuapr2020.html
2019-04-03
Published