CVE-2019-19926NULL Pointer Dereference in Sqlite

Severity
7.5HIGHNVD
EPSS
8.3%
top 7.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 23
Latest updateMay 24

Description

multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsing, as demonstrated by errors from sqlite3WindowRewrite() calls. NOTE: this vulnerability exists because of an incomplete fix for CVE-2019-19880.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages9 packages

NVDsqlite/sqlite3.30.1
Debianchromium/chromium< 80.0.3987.106-1+3
NVDopensuse/leap15.1

Also affects: Debian Linux 10.0, 9.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-vjff-gpgv-hf96: multiSelect in select2022-05-24
OSV
CVE-2019-19926: multiSelect in select2019-12-23
CVEList
CVE-2019-19926: multiSelect in select2019-12-23

📋Vendor Advisories

5
Ubuntu
SQLite vulnerabilities2020-08-03
Ubuntu
SQLite vulnerabilities2020-03-10
Red Hat
sqlite: error mishandling because of incomplete fix of CVE-2019-198802019-12-20
Microsoft
multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsing, as demonstrated by errors from sqlite3WindowRewrite() calls. NOTE: this vulnerability exists because of an incomplete2019-12-10
Debian
CVE-2019-19926: chromium - multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsin...2019

💬Community

14
Bugzilla
CVE-2019-19926 nodejs-sqlite3: SQLite: error mishandling because of incomplete fix of CVE-2019-19880 [fedora-all]2020-01-09
Bugzilla
CVE-2019-19926 mingw-sqlite: SQLite: error mishandling because of incomplete fix of CVE-2019-19880 [epel-7]2020-01-09
Bugzilla
CVE-2019-19926 sqlite2: SQLite: error mishandling because of incomplete fix of CVE-2019-19880 [fedora-all]2020-01-09
Bugzilla
CVE-2019-19926 libsqlite3x: SQLite: error mishandling because of incomplete fix of CVE-2019-19880 [fedora-all]2020-01-09
Bugzilla
CVE-2019-19926 libsqlite3x: SQLite: error mishandling because of incomplete fix of CVE-2019-19880 [fedora-all]2020-01-09
CVE-2019-19926 — NULL Pointer Dereference in Sqlite | cvebase