CVE-2019-8457
published 2019-05-30CVE-2019-8457: SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree tables.
PriorityP359critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
45.43%
98.7th percentile
SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree tables.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | db5.3 | < db5.3 5.3.28+dfsg1-0.9 (bookworm) | db5.3 5.3.28+dfsg1-0.9 (bookworm) |
| debian | sqlite3 | < db5.3 5.3.28+dfsg1-0.9 (bookworm) | db5.3 5.3.28+dfsg1-0.9 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| ghost | sqlite3 | >= 0 < 3.27.2-3 | 3.27.2-3 |
| ghost | sqlite3 | >= 0 < 3.27.2-3 | 3.27.2-3 |
| ghost | sqlite3 | >= 0 < 3.27.2-3 | 3.27.2-3 |
| ghost | sqlite3 | >= 0 < 3.27.2-3 | 3.27.2-3 |
| ghost | sqlite3 | >= 0 < 3.11.0-1ubuntu1.2 | 3.11.0-1ubuntu1.2 |
| ghost | sqlite3 | >= 0 < 3.22.0-1ubuntu0.1 | 3.22.0-1ubuntu0.1 |
| ghost | sqlite3 | >= 0 < 3.8.2-1ubuntu2.2+esm1 | 3.8.2-1ubuntu2.2+esm1 |
| android | — | — | |
| msrc | azl3_ceph_16.2.10-3_on_azure_linux_3.0 | — | — |
| msrc | azl3_ceph_18.2.1-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_heimdal_7.8.0-3_on_azure_linux_3.0 | — | — |
| msrc | azl3_libdb_5.3.28-9_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_ceph_16.2.10-7_on_cbl_mariner_2.0 | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_msrc9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Berkeley DB Risk Matrix: Data Store (SQLite) — CVE-2019-8457
vendor_oracle·2020-07-15·CVSS 9.8
CVE-2019-8457 [CRITICAL] Oracle Oracle Berkeley DB Risk Matrix: Data Store (SQLite) — CVE-2019-8457
Oracle Oracle Berkeley DB Risk Matrix: Data Store (SQLite) vulnerability
CVE: CVE-2019-8457
CVSS: 0.0
Protocol: TCP
Remote exploit: No
Affected versions: Network
Advisory: cpujul2020 (JUL 2020)
Android
CVE-2019-8457: Android Security Bulletin 2020-04-01
CVE: CVE-2019-8457
Severity: HIGH
Type: ID
Affected AOSP versions: 8
vendor_android·2020-04-01·CVSS 9.8
CVE-2019-8457 [CRITICAL] CVE-2019-8457: Android Security Bulletin 2020-04-01
CVE: CVE-2019-8457
Severity: HIGH
Type: ID
Affected AOSP versions: 8
Android Security Bulletin 2020-04-01
CVE: CVE-2019-8457
Severity: HIGH
Type: ID
Affected AOSP versions: 8.0, 8.1, 9, 10
References: A-140182003
[2]
Oracle
Oracle Oracle Communications Applications Risk Matrix: Tools (SQLite) — CVE-2019-8457
vendor_oracle·2020-01-15·CVSS 9.8
CVE-2019-8457 [CRITICAL] Oracle Oracle Communications Applications Risk Matrix: Tools (SQLite) — CVE-2019-8457
Oracle Oracle Communications Applications Risk Matrix: Tools (SQLite) vulnerability
CVE: CVE-2019-8457
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2020 (JAN 2020)
Ubuntu
SQLite vulnerabilities
vendor_ubuntu·2019-06-19·CVSS 5.9
CVE-2016-6153 [MEDIUM] SQLite vulnerabilities
Title: SQLite vulnerabilities
Summary: Several security issues were fixed in SQLite.
USN-4019-1 fixed several vulnerabilities in sqlite3. This update provides
the corresponding update for Ubuntu 12.04 ESM and 14.04 ESM.
Original advisory details:
It was discovered that SQLite incorrectly handled certain SQL files.
An attacker could possibly use this issue to execute arbitrary code
or cause a denial of service. (CVE-2017-2518)
It was discovered that SQLite incorrectly handled certain queries.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2018-20346, CVE-2018-20506)
It was discovered that SQLite incorrectly handled certain inputs.
An attacker could possibly use this issue to access sensitive information.
(CVE-2019-8457)
It was discovered that SQLite incorre
Ubuntu
SQLite vulnerabilities
vendor_ubuntu·2019-06-19·CVSS 5.9
CVE-2016-6153 [MEDIUM] SQLite vulnerabilities
Title: SQLite vulnerabilities
Summary: Several security issues were fixed in SQLite.
It was discovered that SQLite incorrectly handled certain SQL files.
An attacker could possibly use this issue to execute arbitrary code
or cause a denial of service. This issue only affected Ubuntu 16.04
LTS. (CVE-2017-2518, CVE-2017-2520)
It was discovered that SQLite incorrectly handled certain queries.
An attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 18.04 LTS and Ubuntu 18.10. (CVE-2018-20505)
It was discovered that SQLite incorrectly handled certain queries.
An attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and
Ubuntu 18.10. (CVE-2018-20346, CVE-2018-20506)
It was di
Ubuntu
Berkeley DB vulnerability
vendor_ubuntu·2019-06-04
CVE-2019-8457 Berkeley DB vulnerability
Title: Berkeley DB vulnerability
Summary: Berkeley DB could be made to expose sensitive information.
It was discovered that Berkeley DB incorrectly handled certain inputs.
An attacker could possibly use this issue to read sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Berkeley DB vulnerability
vendor_ubuntu·2019-06-04
CVE-2019-8457 Berkeley DB vulnerability
Title: Berkeley DB vulnerability
Summary: Berkeley DB could be made to expose sensitive information.
USN-4004-1 fixed a vulnerability in Berkeley DB. This update provides
the corresponding update for Ubuntu 14.04 ESM.
Original advisory details:
It was discovered that Berkeley DB incorrectly handled certain inputs.
An attacker could possibly use this issue to read sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree tables.
vendor_msrc·2019-05-14·CVSS 9.8
CVE-2019-8457 [CRITICAL] CWE-125 SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree tables.
SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree tables.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
checkpoint: c
Red Hat
sqlite: heap out-of-bound read in function rtreenode()
vendor_redhat·2019-03-20·CVSS 9.8
CVE-2019-8457 [CRITICAL] CWE-125 sqlite: heap out-of-bound read in function rtreenode()
sqlite: heap out-of-bound read in function rtreenode()
SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree tables.
Package: sqlite (Red Hat Enterprise Linux 5) - Not affected
Package: sqlite (Red Hat Enterprise Linux 6) - Out of support scope
Package: sqlite (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2019-8457: db5.3 - SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound re...
vendor_debian·2019·CVSS 9.8
CVE-2019-8457 [CRITICAL] CVE-2019-8457: db5.3 - SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound re...
SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree tables.
Scope: local
bookworm: resolved (fixed in 5.3.28+dfsg1-0.9)
bullseye: open
forky: resolved (fixed in 5.3.28+dfsg1-0.9)
sid: resolved (fixed in 5.3.28+dfsg1-0.9)
trixie: resolved (fixed in 5.3.28+dfsg1-0.9)
GHSA
GHSA-p4jx-5p2x-4pq7: SQLite3 from 3
ghsa_unreviewed·2022-05-24
CVE-2019-8457 [CRITICAL] CWE-125 GHSA-p4jx-5p2x-4pq7: SQLite3 from 3
SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree tables.
OSV
sqlite3 vulnerabilities
osv·2019-06-19·CVSS 5.9
CVE-2017-2518 [MEDIUM] sqlite3 vulnerabilities
sqlite3 vulnerabilities
It was discovered that SQLite incorrectly handled certain SQL files.
An attacker could possibly use this issue to execute arbitrary code
or cause a denial of service. This issue only affected Ubuntu 16.04
LTS. (CVE-2017-2518, CVE-2017-2520)
It was discovered that SQLite incorrectly handled certain queries.
An attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 18.04 LTS and Ubuntu 18.10. (CVE-2018-20505)
It was discovered that SQLite incorrectly handled certain queries.
An attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and
Ubuntu 18.10. (CVE-2018-20346, CVE-2018-20506)
It was discovered that SQLite incorrectly handled certain inputs.
An at
OSV
sqlite3 vulnerabilities
osv·2019-06-19·CVSS 5.9
CVE-2017-2518 [MEDIUM] sqlite3 vulnerabilities
sqlite3 vulnerabilities
USN-4019-1 fixed several vulnerabilities in sqlite3. This update provides
the corresponding update for Ubuntu 12.04 ESM and 14.04 ESM.
Original advisory details:
It was discovered that SQLite incorrectly handled certain SQL files.
An attacker could possibly use this issue to execute arbitrary code
or cause a denial of service. (CVE-2017-2518)
It was discovered that SQLite incorrectly handled certain queries.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2018-20346, CVE-2018-20506)
It was discovered that SQLite incorrectly handled certain inputs.
An attacker could possibly use this issue to access sensitive information.
(CVE-2019-8457)
It was discovered that SQLite incorrectly handled certain inputs.
An attacker could possibly use th
OSV
CVE-2019-8457: SQLite3 from 3
osv·2019-05-30·CVSS 9.8
CVE-2019-8457 [CRITICAL] CVE-2019-8457: SQLite3 from 3
SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree tables.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-8457 sqlite: sqlite3: heap out-of-bound read in function rtreenode() [fedora-all]
bugzilla·2019-06-11·CVSS 9.8
CVE-2019-8457 [CRITICAL] CVE-2019-8457 sqlite: sqlite3: heap out-of-bound read in function rtreenode() [fedora-all]
CVE-2019-8457 sqlite: sqlite3: heap out-of-bound read in function rtreenode() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppo
Bugzilla
CVE-2019-8457 sqlite: heap out-of-bound read in function rtreenode()
bugzilla·2019-06-04·CVSS 9.8
CVE-2019-8457 [CRITICAL] CVE-2019-8457 sqlite: heap out-of-bound read in function rtreenode()
CVE-2019-8457 sqlite: heap out-of-bound read in function rtreenode()
SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound
read in the rtreenode() function when handling invalid rtree tables.
Upstream commit:
https://www.sqlite.org/src/info/90acdbfce9c08858
Discussion:
Created sqlite3 tracking bugs for this issue:
Affects: fedora-all [bug 1716883]
Created sqlite3-dbf tracking bugs for this issue:
Affects: fedora-all [bug 1716884]
---
Created sqlite3-dbf tracking bugs for this issue:
Affects: epel-all [bug 1716885]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.
---
Bugzilla
CVE-2019-8457 sqlite3: heap out-of-bound read in function rtreenode() [fedora-all]
bugzilla·2019-06-04·CVSS 9.8
CVE-2019-8457 [CRITICAL] CVE-2019-8457 sqlite3: heap out-of-bound read in function rtreenode() [fedora-all]
CVE-2019-8457 sqlite3: heap out-of-bound read in function rtreenode() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ver
Bugzilla
CVE-2019-8457 sqlite3-dbf: sqlite3: heap out-of-bound read in function rtreenode() [fedora-all]
bugzilla·2019-06-04·CVSS 9.8
CVE-2019-8457 [CRITICAL] CVE-2019-8457 sqlite3-dbf: sqlite3: heap out-of-bound read in function rtreenode() [fedora-all]
CVE-2019-8457 sqlite3-dbf: sqlite3: heap out-of-bound read in function rtreenode() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple
Bugzilla
CVE-2019-8457 sqlite3-dbf: sqlite3: heap out-of-bound read in function rtreenode() [epel-all]
bugzilla·2019-06-04·CVSS 9.8
CVE-2019-8457 [CRITICAL] CVE-2019-8457 sqlite3-dbf: sqlite3: heap out-of-bound read in function rtreenode() [epel-all]
CVE-2019-8457 sqlite3-dbf: sqlite3: heap out-of-bound read in function rtreenode() [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supp
Tenable
Oracle January 2020 Critical Patch Update Contains 255 CVEs
blogs_tenable·2020-01-15
Oracle January 2020 Critical Patch Update Contains 255 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Oracle Critical Patch Update for October Contains 180 Fixes
blogs_tenable·2019-10-16
Oracle Critical Patch Update for October Contains 180 Fixes
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Checkpoint
SELECT code_execution FROM * USING SQLite;
blogs_checkpoint·2019-08-10
CVE-2019-8457 SELECT code_execution FROM * USING SQLite;
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
AI Research 2
Android Malware 23
Artificial Intelligence 4
ChatGPT 3
Check Point Research Publications 455
Cloud Security 1
CPRadio 44
Crypto 2
Data & Threat Intelligence 2
Data Analysis 0
Demos 22
Global Cyber Attack Reports 408
How To Guides 13
Ransomware 5
Russo-Ukrainian War 1
Security Report 1
Threat and data analysis 0
Threat Research 174
Web 3.0 Security 11
Wipers 0
## SELECT code_execution FROM * USING SQLite;
## Gaining code execution using a malicious SQLite database
Research By: Omer Gull
## tl;dr
SQLite is one of the most deployed software in
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00074.htmlhttps://kc.mcafee.com/corporate/index?page=content&id=SB10365https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OPKYSWCOM3CL66RI76TYVIG6TJ263RXH/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SJPFGA45DI4F5MCF2OAACGH3HQOF4G3M/https://security.netapp.com/advisory/ntap-20190606-0002/https://usn.ubuntu.com/4004-1/https://usn.ubuntu.com/4004-2/https://usn.ubuntu.com/4019-1/https://usn.ubuntu.com/4019-2/https://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlhttps://www.sqlite.org/releaselog/3_28_0.htmlhttps://www.sqlite.org/src/info/90acdbfce9c08858http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00074.htmlhttps://kc.mcafee.com/corporate/index?page=content&id=SB10365https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OPKYSWCOM3CL66RI76TYVIG6TJ263RXH/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SJPFGA45DI4F5MCF2OAACGH3HQOF4G3M/https://security.netapp.com/advisory/ntap-20190606-0002/https://usn.ubuntu.com/4004-1/https://usn.ubuntu.com/4004-2/https://usn.ubuntu.com/4019-1/https://usn.ubuntu.com/4019-2/https://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlhttps://www.sqlite.org/releaselog/3_28_0.htmlhttps://www.sqlite.org/src/info/90acdbfce9c08858
2019-05-30
Published