CVE-2020-13631

Severity
5.5MEDIUM
EPSS
0.0%
top 85.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 27
Latest updateMay 24

Description

SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c and build.c.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages13 packages

NVDsqlite/sqlite< 3.32.0
Debiansqlite3< 3.32.0-1+3
NVDapple/tvos< 14.0
NVDapple/macos< 11.0.1
NVDapple/icloud< 11.5

Also affects: Fedora 32, Ubuntu Linux 16.04, 18.04, 19.10, 20.04

Patches

🔴Vulnerability Details

3
GHSA
GHSA-ggrr-j79r-pq3m: SQLite before 32022-05-24
CVEList
CVE-2020-13631: SQLite before 32020-05-27
OSV
CVE-2020-13631: SQLite before 32020-05-27

📋Vendor Advisories

9
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Installation (SQLite) — CVE-2020-136312020-10-15
Apple
CVE-2020-13631: tvOS 14.02020-09-16
Apple
CVE-2020-13631: iTunes 12.10.9 for Windows2020-09-16
Apple
CVE-2020-13631: watchOS 7.02020-09-16
BSD
FreeBSD-SA-20:22.sqlite: Multiple vulnerabilities in sqlite32020-08-05

💬Community

4
Bugzilla
CVE-2020-13631 sqlite2: sqlite: virtual table can be renamed into the name of one of its shadow tables [fedora-all]2020-05-29
Bugzilla
CVE-2020-13631 sqlite: allows a virtual table to be renamed to the name of one of its shadow tables [fedora-all]2020-05-29
Bugzilla
CVE-2020-13631 sqlite: Virtual table can be renamed into the name of one of its shadow tables2020-05-29
Bugzilla
CVE-2020-13631 mingw-sqlite: sqlite: virtual table can be renamed into the name of one of its shadow tables [fedora-all]2020-05-29
CVE-2020-13631 (MEDIUM CVSS 5.5) | SQLite before 3.32.0 allows a virtu | cvebase.io