CVE-2019-16168

CWE-36915 documents10 sources
Severity
6.5MEDIUM
EPSS
0.8%
top 25.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 9
Latest updateMay 24

Description

In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validation of a sqlite_stat1 sz field, aka a "severe division by zero in the query planner."

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages14 packages

Debiansqlite3< 3.29.0-2+3
Ubuntusqlite3< 3.11.0-1ubuntu1.3+1
NVDsqlite/sqlite3.8.53.29.0
NVDoracle/mysql8.0.08.0.18

Also affects: Debian Linux 9.0, Fedora 30, Ubuntu Linux 12.04, 16.04, 18.04, 19.04, 19.10

Patches

🔴Vulnerability Details

4
GHSA
GHSA-m2vp-56p6-9q2h: In SQLite through 32022-05-24
OSV
sqlite3 vulnerabilities2019-12-02
OSV
CVE-2019-16168: In SQLite through 32019-09-09
CVEList
CVE-2019-16168: In SQLite through 32019-09-09

📋Vendor Advisories

6
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: DC-Specific Component (SQLite) — CVE-2019-161682020-04-15
Oracle
Oracle Oracle Communications Applications Risk Matrix: Core (SQLite) — CVE-2019-161682020-01-15
Ubuntu
SQLite vulnerabilities2019-12-02
Microsoft
In SQLite through 3.29.0 whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validation of a sqlite_stat1 sz field aka a "severe division by zero in the que2019-09-10
Red Hat
sqlite: Division by zero in whereLoopAddBtreeIndex in sqlite3.c2019-08-15

💬Community

4
Bugzilla
CVE-2019-16168 mingw-sqlite: sqlite: division by zero in whereLoopAddBtreeIndex in sqlite3.c [epel-7]2019-11-05
Bugzilla
CVE-2019-16168 mingw-sqlite: sqlite: division by zero in whereLoopAddBtreeIndex in sqlite3.c [fedora-all]2019-11-05
Bugzilla
CVE-2019-16168 sqlite: Division by zero in whereLoopAddBtreeIndex in sqlite3.c2019-11-05
Bugzilla
CVE-2019-16168 sqlite: division by zero in whereLoopAddBtreeIndex in sqlite3.c [fedora-all]2019-11-05