CVE-2019-19242
published 2019-11-27CVE-2019-19242: SQLite 3.30.1 mishandles pExpr->y.pTab, as demonstrated by the TK_COLUMN case in sqlite3ExprCodeTarget in expr.c.
medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
SQLite 3.30.1 mishandles pExpr->y.pTab, as demonstrated by the TK_COLUMN case in sqlite3ExprCodeTarget in expr.c.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | sqlite3 | < sqlite3 3.30.1+fossil191229-1 (bookworm) | sqlite3 3.30.1+fossil191229-1 (bookworm) |
| ghost | sqlite3 | >= 0 < 3.30.1+fossil191229-1 | 3.30.1+fossil191229-1 |
| ghost | sqlite3 | >= 0 < 3.30.1+fossil191229-1 | 3.30.1+fossil191229-1 |
| ghost | sqlite3 | >= 0 < 3.30.1+fossil191229-1 | 3.30.1+fossil191229-1 |
| ghost | sqlite3 | >= 0 < 3.30.1+fossil191229-1 | 3.30.1+fossil191229-1 |
| ghost | sqlite3 | >= 0 < 3.11.0-1ubuntu1.3 | 3.11.0-1ubuntu1.3 |
| ghost | sqlite3 | >= 0 < 3.22.0-1ubuntu0.2 | 3.22.0-1ubuntu0.2 |
| oracle | mysql_workbench | <= 8.0.19 | — |
| redhat | enterprise_linux | — | — |
| siemens | sinec_infrastructure_network_services | < 1.0.1.1 | 1.0.1.1 |
| sqlite | sqlite | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH