cbcvebase.
CVE-2020-13871
published 2020-06-06

CVE-2020-13871: SQLite 3.32.2 has a use-after-free in resetAccumulator in select.c because the parse tree rewrite for window functions is too late.

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
SQLite 3.32.2 has a use-after-free in resetAccumulator in select.c because the parse tree rewrite for window functions is too late.

Affected

19 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiansqlite3< sqlite3 3.32.2-2 (bookworm)sqlite3 3.32.2-2 (bookworm)
fedoraprojectfedora
ghostsqlite3>= 0 < 3.32.2-23.32.2-2
ghostsqlite3>= 0 < 3.32.2-23.32.2-2
ghostsqlite3>= 0 < 3.32.2-23.32.2-2
ghostsqlite3>= 0 < 3.32.2-23.32.2-2
googleandroid
googlechrome_chrome
oraclecommunications_messaging_server
oraclecommunications_network_charging_and_control
oraclecommunications_network_charging_and_control
oracleenterprise_manager_ops_center
oraclehyperion_infrastructure_technology
oraclemysql_workbench<= 8.0.22
oraclezfs_storage_appliance_kit
platformexternal_sqlite>= 11:0 < 11:2021-11-0111:2021-11-01
siemenssinec_infrastructure_network_services< 1.0.1.11.0.1.1
sqlitesqlite

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH