CVE-2019-20218
published 2020-01-02CVE-2019-20218: selectExpander in select.c in SQLite 3.30.1 proceeds with WITH stack unwinding even after a parsing error.
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.62%
88.2th percentile
selectExpander in select.c in SQLite 3.30.1 proceeds with WITH stack unwinding even after a parsing error.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | sqlite3 | < sqlite3 3.30.1+fossil191229-1 (bookworm) | sqlite3 3.30.1+fossil191229-1 (bookworm) |
| ghost | sqlite3 | >= 0 < 3.30.1+fossil191229-1 | 3.30.1+fossil191229-1 |
| ghost | sqlite3 | >= 0 < 3.30.1+fossil191229-1 | 3.30.1+fossil191229-1 |
| ghost | sqlite3 | >= 0 < 3.30.1+fossil191229-1 | 3.30.1+fossil191229-1 |
| ghost | sqlite3 | >= 0 < 3.30.1+fossil191229-1 | 3.30.1+fossil191229-1 |
| ghost | sqlite3 | >= 0 < 3.11.0-1ubuntu1.4 | 3.11.0-1ubuntu1.4 |
| ghost | sqlite3 | >= 0 < 3.22.0-1ubuntu0.3 | 3.22.0-1ubuntu0.3 |
| oracle | mysql_workbench | <= 8.0.19 | — |
| sqlite | sqlite | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
Ubuntu
SQLite vulnerabilities
vendor_ubuntu·2020-03-10·CVSS 8.8
CVE-2019-13734 [HIGH] SQLite vulnerabilities
Title: SQLite vulnerabilities
Summary: Several security issues were fixed in SQLite.
It was discovered that SQLite incorrectly handled certain shadow tables. An
attacker could use this issue to cause SQLite to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2019-13734,
CVE-2019-13750, CVE-2019-13753)
It was discovered that SQLite incorrectly handled certain corrupt records.
An attacker could use this issue to cause SQLite to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2019-13751)
It was discovered that SQLite incorrectly handled certain queries. An
attacker could use this issue to cause SQLite to crash, resulting in a
denial of service, or possibly execute arbitrary code. This issue only
affected Ubuntu 19.10. (CVE
Red Hat
sqlite: selectExpander in select.c proceeds with WITH stack unwinding even after a parsing error
vendor_redhat·2020-01-02·CVSS 7.5
CVE-2019-20218 [HIGH] CWE-391 sqlite: selectExpander in select.c proceeds with WITH stack unwinding even after a parsing error
sqlite: selectExpander in select.c proceeds with WITH stack unwinding even after a parsing error
selectExpander in select.c in SQLite 3.30.1 proceeds with WITH stack unwinding even after a parsing error.
Package: sqlite (Red Hat Enterprise Linux 5) - Out of support scope
Package: sqlite (Red Hat Enterprise Linux 6) - Out of support scope
Package: sqlite (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2019-20218: sqlite3 - selectExpander in select.c in SQLite 3.30.1 proceeds with WITH stack unwinding e...
vendor_debian·2019·CVSS 7.5
CVE-2019-20218 [HIGH] CVE-2019-20218: sqlite3 - selectExpander in select.c in SQLite 3.30.1 proceeds with WITH stack unwinding e...
selectExpander in select.c in SQLite 3.30.1 proceeds with WITH stack unwinding even after a parsing error.
Scope: local
bookworm: resolved (fixed in 3.30.1+fossil191229-1)
bullseye: resolved (fixed in 3.30.1+fossil191229-1)
forky: resolved (fixed in 3.30.1+fossil191229-1)
sid: resolved (fixed in 3.30.1+fossil191229-1)
trixie: resolved (fixed in 3.30.1+fossil191229-1)
GHSA
GHSA-vrgp-3vgj-937c: selectExpander in select
ghsa_unreviewed·2022-05-24
CVE-2019-20218 [HIGH] CWE-755 GHSA-vrgp-3vgj-937c: selectExpander in select
selectExpander in select.c in SQLite 3.30.1 proceeds with WITH stack unwinding even after a parsing error.
OSV
sqlite3 vulnerabilities
osv·2020-03-10·CVSS 8.8
CVE-2019-13734 [HIGH] sqlite3 vulnerabilities
sqlite3 vulnerabilities
It was discovered that SQLite incorrectly handled certain shadow tables. An
attacker could use this issue to cause SQLite to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2019-13734,
CVE-2019-13750, CVE-2019-13753)
It was discovered that SQLite incorrectly handled certain corrupt records.
An attacker could use this issue to cause SQLite to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2019-13751)
It was discovered that SQLite incorrectly handled certain queries. An
attacker could use this issue to cause SQLite to crash, resulting in a
denial of service, or possibly execute arbitrary code. This issue only
affected Ubuntu 19.10. (CVE-2019-19880)
It was discovered that SQLite incorrectly handle
OSV
CVE-2019-20218: selectExpander in select
osv·2020-01-02·CVSS 7.5
CVE-2019-20218 [HIGH] CVE-2019-20218: selectExpander in select
selectExpander in select.c in SQLite 3.30.1 proceeds with WITH stack unwinding even after a parsing error.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-20218 mingw-sqlite: sqlite: selectExpander in select.c proceeds with WITH stack unwinding even after a parsing error [epel-7]
bugzilla·2020-01-15·CVSS 7.5
CVE-2019-20218 [HIGH] CVE-2019-20218 mingw-sqlite: sqlite: selectExpander in select.c proceeds with WITH stack unwinding even after a parsing error [epel-7]
CVE-2019-20218 mingw-sqlite: sqlite: selectExpander in select.c proceeds with WITH stack unwinding even after a parsing error [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Bugzilla
CVE-2019-20218 sqlite: selectExpander in select.c proceeds with WITH stack unwinding even after a parsing error
bugzilla·2020-01-15·CVSS 7.5
CVE-2019-20218 [HIGH] CVE-2019-20218 sqlite: selectExpander in select.c proceeds with WITH stack unwinding even after a parsing error
CVE-2019-20218 sqlite: selectExpander in select.c proceeds with WITH stack unwinding even after a parsing error
selectExpander in select.c in SQLite 3.30.1 proceeds with WITH stack unwinding even after a parsing error.
Reference and upstream commit:
https://github.com/sqlite/sqlite/commit/a6c1a71cde082e09750465d5675699062922e387
Discussion:
Created mingw-sqlite tracking bugs for this issue:
Affects: epel-7 [bug 1791315]
Affects: fedora-all [bug 1791316]
Created sqlite tracking bugs for this issue:
Affects: fedora-all [bug 1791317]
---
There seems to be a reproducer in the upstream commit:
[huzaifas@babylon ~]$ cat a.sql
CREATE TABLE v0 (a);
CREATE VIEW v2 (v3) AS WITH x1 AS (SELECT * FROM v2) SELECT v3 AS x, v3 AS y FROM v2;
SELECT * FROM v2;
[huzaifas@babylon ~]$ sqlite3 < a.sq
Bugzilla
CVE-2019-20218 sqlite: selectExpander in select.c proceeds with WITH stack unwinding even after a parsing error [fedora-all]
bugzilla·2020-01-15·CVSS 7.5
CVE-2019-20218 [HIGH] CVE-2019-20218 sqlite: selectExpander in select.c proceeds with WITH stack unwinding even after a parsing error [fedora-all]
CVE-2019-20218 sqlite: selectExpander in select.c proceeds with WITH stack unwinding even after a parsing error [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE:
Bugzilla
CVE-2019-20218 mingw-sqlite: sqlite: selectExpander in select.c proceeds with WITH stack unwinding even after a parsing error [fedora-all]
bugzilla·2020-01-15·CVSS 7.5
CVE-2019-20218 [HIGH] CVE-2019-20218 mingw-sqlite: sqlite: selectExpander in select.c proceeds with WITH stack unwinding even after a parsing error [fedora-all]
CVE-2019-20218 mingw-sqlite: sqlite: selectExpander in select.c proceeds with WITH stack unwinding even after a parsing error [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit m
https://github.com/sqlite/sqlite/commit/a6c1a71cde082e09750465d5675699062922e387https://lists.debian.org/debian-lts-announce/2020/08/msg00037.htmlhttps://lists.debian.org/debian-lts-announce/2020/12/msg00016.htmlhttps://security.gentoo.org/glsa/202007-26https://usn.ubuntu.com/4298-1/https://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://github.com/sqlite/sqlite/commit/a6c1a71cde082e09750465d5675699062922e387https://lists.debian.org/debian-lts-announce/2020/08/msg00037.htmlhttps://lists.debian.org/debian-lts-announce/2020/12/msg00016.htmlhttps://security.gentoo.org/glsa/202007-26https://usn.ubuntu.com/4298-1/https://www.oracle.com/security-alerts/cpuapr2020.html
2020-01-02
Published