CVE-2020-11656Use After Free in Sqlite

CWE-416Use After Free15 documents10 sources
Severity
9.8CRITICALNVD
EPSS
6.1%
top 9.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 9
Latest updateMay 24

Description

In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a compound SELECT statement.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages12 packages

Debianghost/sqlite3< 3.32.0-1+3
NVDsqlite/sqlite3.31.1
NVDoracle/mysql8.0.08.0.22
NVDtenable/tenable.sc5.19.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-x2v5-p27f-53wp: In SQLite through 32022-05-24
OSV
CVE-2020-11656: In SQLite through 32020-04-09
CVEList
CVE-2020-11656: In SQLite through 32020-04-09

📋Vendor Advisories

5
BSD
FreeBSD-SA-20:22.sqlite: Multiple vulnerabilities in sqlite32020-08-05
Oracle
Oracle Oracle Communications Applications Risk Matrix: Data Access Pack (SQLite) — CVE-2020-116562020-07-15
Microsoft
In SQLite through 3.31.1 the ALTER TABLE implementation has a use-after-free as demonstrated by an ORDER BY clause that belongs to a compound SELECT statement.2020-04-14
Red Hat
sqlite: use-after-free in the ALTER TABLE implementation2020-04-03
Debian
CVE-2020-11656: sqlite3 - In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, a...2020

💬Community

6
Bugzilla
CVE-2020-11656 sqlite: use-after-free in the ALTER TABLE implementation [fedora-all]2020-05-26
Bugzilla
CVE-2020-11656 sqlite2: sqlite: use-after-free in the ALTER TABLE implementation [epel-all]2020-04-15
Bugzilla
CVE-2020-11656 sqlite3: sqlite: use-after-free in the ALTER TABLE implementation [fedora-all]2020-04-15
Bugzilla
CVE-2020-11656 sqlite2: sqlite: use-after-free in the ALTER TABLE implementation [fedora-all]2020-04-15
Bugzilla
CVE-2020-11656 mingw-sqlite: sqlite: use-after-free in the ALTER TABLE implementation [fedora-all]2020-04-15
CVE-2020-11656 — Use After Free in Sqlite | cvebase