CVE-2019-19880NULL Pointer Dereference in Sqlite

Severity
7.5HIGHNVD
EPSS
8.4%
top 7.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 18
Latest updateMay 24

Description

exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values in ORDER BY clauses of window definitions are mishandled.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages10 packages

Debianghost/sqlite3< 3.30.1+fossil191229-1+3
NVDsqlite/sqlite3.30.1
Debianchromium/chromium< 80.0.3987.106-1+3

Also affects: Debian Linux 10.0, 9.0

Patches

🔴Vulnerability Details

4
GHSA
GHSA-mpvh-7x64-2fc7: exprListAppendList in window2022-05-24
OSV
sqlite3 vulnerabilities2020-03-10
OSV
CVE-2019-19880: exprListAppendList in window2019-12-18
CVEList
CVE-2019-19880: exprListAppendList in window2019-12-18

📋Vendor Advisories

4
Ubuntu
SQLite vulnerabilities2020-03-10
Red Hat
sqlite: error mishandling because of incomplete fix of CVE-2019-198802019-12-20
Red Hat
sqlite: invalid pointer dereference in exprListAppendList in window.c2019-12-17
Debian
CVE-2019-19880: chromium - exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an i...2019

💬Community

18
Bugzilla
CVE-2019-19926 nodejs-sqlite3: SQLite: error mishandling because of incomplete fix of CVE-2019-19880 [fedora-all]2020-01-09
Bugzilla
CVE-2019-19926 mingw-sqlite: SQLite: error mishandling because of incomplete fix of CVE-2019-19880 [epel-7]2020-01-09
Bugzilla
CVE-2019-19926 sqlite2: SQLite: error mishandling because of incomplete fix of CVE-2019-19880 [fedora-all]2020-01-09
Bugzilla
CVE-2019-19926 libsqlite3x: SQLite: error mishandling because of incomplete fix of CVE-2019-19880 [fedora-all]2020-01-09
Bugzilla
CVE-2019-19926 libsqlite3x: SQLite: error mishandling because of incomplete fix of CVE-2019-19880 [fedora-all]2020-01-09
CVE-2019-19880 — NULL Pointer Dereference in Sqlite | cvebase