CVE-2019-19959Null Byte Interaction Error (Poison Null Byte) in Sqlite

Severity
7.5HIGHNVD
EPSS
0.5%
top 33.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 3
Latest updateMay 24

Description

ext/misc/zipfile.c in SQLite 3.30.1 mishandles certain uses of INSERT INTO in situations involving embedded '\0' characters in filenames, leading to a memory-management error that can be detected by (for example) valgrind.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

Debianghost/sqlite3< 3.30.1+fossil191229-1+3
NVDsqlite/sqlite3.30.1

Also affects: Ubuntu Linux 16.04, 18.04, 19.10

Patches

🔴Vulnerability Details

3
GHSA
GHSA-8q6c-j3g3-gr6j: ext/misc/zipfile2022-05-24
OSV
CVE-2019-19959: ext/misc/zipfile2020-01-03
CVEList
CVE-2019-19959: ext/misc/zipfile2020-01-03

📋Vendor Advisories

3
Ubuntu
SQLite vulnerabilities2020-03-10
Red Hat
sqlite: mishandles certain uses of INSERT INTO in situations involving embedded '\0' characters in filenames2019-12-23
Debian
CVE-2019-19959: sqlite3 - ext/misc/zipfile.c in SQLite 3.30.1 mishandles certain uses of INSERT INTO in si...2019

💬Community

4
Bugzilla
CVE-2019-19959 mingw-sqlite: sqlite: mishandles certain uses of INSERT INTO in situations involving embedded '\0' characters in filenames [epel-7]2020-01-09
Bugzilla
CVE-2019-19959 mingw-sqlite: sqlite: mishandles certain uses of INSERT INTO in situations involving embedded '\0' characters in filenames [fedora-all]2020-01-09
Bugzilla
CVE-2019-19959 sqlite: mishandles certain uses of INSERT INTO in situations involving embedded '\0' characters in filenames2020-01-09
Bugzilla
CVE-2019-19959 sqlite: mishandles certain uses of INSERT INTO in situations involving embedded '\0' characters in filenames [fedora-all]2020-01-09
CVE-2019-19959 — Sqlite vulnerability | cvebase