cbcvebase.
CVE-2020-13434
published 2020-05-24

CVE-2020-13434: SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c.

medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c.

Affected

43 ranges· showing 25
VendorProductVersion rangeFixed in
appleicloud< 11.511.5
appleipados< 14.014.0
appleiphone_os< 14.014.0
appleitunes< 12.10.912.10.9
appleitunes_12.10.9_for_windows
applemacos>= 11.0 < 11.0.111.0.1
appletvos< 14.014.0
appletvos
applewatchos< 7.07.0
applewatchos
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debiansqlite3< sqlite3 3.32.1-1 (bookworm)sqlite3 3.32.1-1 (bookworm)
fedoraprojectfedora
freebsdfreebsd
freebsdfreebsd
freebsdfreebsd
freebsdfreebsd>= 11.0 < 11.411.4
ghostsqlite3>= 0 < 3.32.1-13.32.1-1
ghostsqlite3>= 0 < 3.32.1-13.32.1-1
ghostsqlite3>= 0 < 3.32.1-13.32.1-1

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH