CVE-2019-19925
published 2019-12-24CVE-2019-19925: zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive.
high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 80.0.3987.106-1 | 80.0.3987.106-1 |
| chromium | chromium | >= 0 < 80.0.3987.106-1 | 80.0.3987.106-1 |
| chromium | chromium | >= 0 < 80.0.3987.106-1 | 80.0.3987.106-1 |
| chromium | chromium | >= 0 < 80.0.3987.106-1 | 80.0.3987.106-1 |
| debian | chromium | < chromium 80.0.3987.106-1 (bookworm) | chromium 80.0.3987.106-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | sqlite3 | < chromium 80.0.3987.106-1 (bookworm) | chromium 80.0.3987.106-1 (bookworm) |
| ghost | sqlite3 | >= 0 < 3.30.1+fossil191229-1 | 3.30.1+fossil191229-1 |
| ghost | sqlite3 | >= 0 < 3.30.1+fossil191229-1 | 3.30.1+fossil191229-1 |
| ghost | sqlite3 | >= 0 < 3.30.1+fossil191229-1 | 3.30.1+fossil191229-1 |
| ghost | sqlite3 | >= 0 < 3.30.1+fossil191229-1 | 3.30.1+fossil191229-1 |
| ghost | sqlite3 | >= 0 < 3.11.0-1ubuntu1.4 | 3.11.0-1ubuntu1.4 |
| ghost | sqlite3 | >= 0 < 3.22.0-1ubuntu0.3 | 3.22.0-1ubuntu0.3 |
| chrome_chrome | — | — | |
| opensuse | backports_sle | — | — |
| opensuse | leap | — | — |
| oracle | mysql_workbench | <= 8.0.19 | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| siemens | sinec_infrastructure_network_services | < 1.0.1.1 | 1.0.1.1 |
| sqlite | sqlite | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH