CVE-2020-35525
published 2022-09-01CVE-2020-35525: In SQlite 3.31.1, a potential null pointer derreference was found in the INTERSEC query processing.
PriorityP434high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.93%
56.5th percentile
In SQlite 3.31.1, a potential null pointer derreference was found in the INTERSEC query processing.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | sqlite3 | < sqlite3 3.32.0-1 (bookworm) | sqlite3 3.32.0-1 (bookworm) |
| ghost | sqlite3 | >= 0 < 3.32.0-1 | 3.32.0-1 |
| ghost | sqlite3 | >= 0 < 3.32.0-1 | 3.32.0-1 |
| ghost | sqlite3 | >= 0 < 3.32.0-1 | 3.32.0-1 |
| ghost | sqlite3 | >= 0 < 3.32.0-1 | 3.32.0-1 |
| ghost | sqlite3 | >= 0 < 3.22.0-1ubuntu0.6 | 3.22.0-1ubuntu0.6 |
| ghost | sqlite3 | >= 0 < 3.31.1-4ubuntu0.4 | 3.31.1-4ubuntu0.4 |
| ghost | sqlite3 | >= 0 < 3.8.2-1ubuntu2.2+esm4 | 3.8.2-1ubuntu2.2+esm4 |
| ghost | sqlite3 | >= 0 < 3.11.0-1ubuntu1.5+esm1 | 3.11.0-1ubuntu1.5+esm1 |
| sqlite | sqlite | — | — |
| sqlite | sqlite | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
sqlite3 vulnerability
osv·2024-06-27·CVSS 7.5
CVE-2020-35525 [HIGH] sqlite3 vulnerability
sqlite3 vulnerability
USN-5615-1 fixed several vulnerabilities in SQLite. This update provides
the corresponding fix for CVE-2020-35525 for Ubuntu 14.04 LTS.
Original advisory details:
It was discovered that SQLite incorrectly handled INTERSEC query
processing. An attacker could use this issue to cause SQLite to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2020-35525)
It was discovered that SQLite incorrectly handled ALTER TABLE for views
that have a nested FROM clause. An attacker could use this issue to cause
SQLite to crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue was only addressed in Ubuntu 20.04 LTS.
(CVE-2020-35527)
It was discovered that SQLite incorrectly handled embedded null characters
when tokeni
OSV
sqlite3 vulnerability
osv·2022-09-28·CVSS 7.5
CVE-2020-35525 [HIGH] sqlite3 vulnerability
sqlite3 vulnerability
USN-5615-1 fixed several vulnerabilities in SQLite. This update provides
the corresponding fix for CVE-2020-35525 for Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that SQLite incorrectly handled INTERSEC query
processing. An attacker could use this issue to cause SQLite to crash,
resulting in a denial of service, or possibly execute arbitrary code.
OSV
sqlite3 vulnerabilities
osv·2022-09-15·CVSS 7.5
CVE-2020-35525 [HIGH] sqlite3 vulnerabilities
sqlite3 vulnerabilities
It was discovered that SQLite incorrectly handled INTERSEC query
processing. An attacker could use this issue to cause SQLite to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2020-35525)
It was discovered that SQLite incorrectly handled ALTER TABLE for views
that have a nested FROM clause. An attacker could use this issue to cause
SQLite to crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue was only addressed in Ubuntu 20.04 LTS.
(CVE-2020-35527)
It was discovered that SQLite incorrectly handled embedded null characters
when tokenizing certain unicode strings. This issue could result in
incorrect results. This issue only affected Ubuntu 20.04 LTS.
(CVE-2021-20223)
GHSA
GHSA-3p6j-m43h-3g48: In SQlite 3
ghsa_unreviewed·2022-09-02
CVE-2020-35525 [HIGH] CWE-476 GHSA-3p6j-m43h-3g48: In SQlite 3
In SQlite 3.31.1, a potential null pointer derreference was found in the INTERSEC query processing.
OSV
CVE-2020-35525: In SQlite 3
osv·2022-09-01·CVSS 7.5
CVE-2020-35525 [HIGH] CVE-2020-35525: In SQlite 3
In SQlite 3.31.1, a potential null pointer derreference was found in the INTERSEC query processing.
Ubuntu
SQLite vulnerability
vendor_ubuntu·2024-06-27·CVSS 7.5
CVE-2020-35525 [HIGH] SQLite vulnerability
Title: SQLite vulnerability
Summary: SQLite could be made to crash or execute arbitrary code.
USN-5615-1 fixed several vulnerabilities in SQLite. This update provides
the corresponding fix for CVE-2020-35525 for Ubuntu 14.04 LTS.
Original advisory details:
It was discovered that SQLite incorrectly handled INTERSEC query
processing. An attacker could use this issue to cause SQLite to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2020-35525)
It was discovered that SQLite incorrectly handled ALTER TABLE for views
that have a nested FROM clause. An attacker could use this issue to cause
SQLite to crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue was only addressed in Ubuntu 20.04 LTS.
(CVE-2020-35527)
It was discov
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
Ubuntu
SQLite vulnerability
vendor_ubuntu·2022-09-28·CVSS 7.5
CVE-2020-35525 [HIGH] SQLite vulnerability
Title: SQLite vulnerability
Summary: SQLite could be made to crash or execute arbitrary code.
USN-5615-1 fixed several vulnerabilities in SQLite. This update provides
the corresponding fix for CVE-2020-35525 for Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that SQLite incorrectly handled INTERSEC query
processing. An attacker could use this issue to cause SQLite to crash,
resulting in a denial of service, or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
SQLite vulnerabilities
vendor_ubuntu·2022-09-15·CVSS 7.5
CVE-2021-20223 [HIGH] SQLite vulnerabilities
Title: SQLite vulnerabilities
Summary: Several security issues were fixed in SQLite.
It was discovered that SQLite incorrectly handled INTERSEC query
processing. An attacker could use this issue to cause SQLite to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2020-35525)
It was discovered that SQLite incorrectly handled ALTER TABLE for views
that have a nested FROM clause. An attacker could use this issue to cause
SQLite to crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue was only addressed in Ubuntu 20.04 LTS.
(CVE-2020-35527)
It was discovered that SQLite incorrectly handled embedded null characters
when tokenizing certain unicode strings. This issue could result in
incorrect results. This issue only affected
Red Hat
sqlite: Null pointer derreference in src/select.c
vendor_redhat·2020-02-20·CVSS 7.5
CVE-2020-35525 [HIGH] CWE-476 sqlite: Null pointer derreference in src/select.c
sqlite: Null pointer derreference in src/select.c
In SQlite 3.31.1, a potential null pointer derreference was found in the INTERSEC query processing.
A NULL pointer dereference flaw was found in select.c of SQLite. An out-of-memory error occurs while an early out on the INTERSECT query is processing. This flaw allows an attacker to execute a potential NULL pointer dereference.
Statement: This flaw is rated as low because this flaw type of vulnerability is believed to require unlikely circumstances to be able to be exploited, or where a successful exploit would give minimal consequences. Also, this flaw is present in a program’s source code but to which no current or theoretically possible, but unproven, exploitation vectors exist or were found during the technical analysis of the flaw.
Debian
CVE-2020-35525: sqlite3 - In SQlite 3.31.1, a potential null pointer derreference was found in the INTERSE...
vendor_debian·2020·CVSS 7.5
CVE-2020-35525 [HIGH] CVE-2020-35525: sqlite3 - In SQlite 3.31.1, a potential null pointer derreference was found in the INTERSE...
In SQlite 3.31.1, a potential null pointer derreference was found in the INTERSEC query processing.
Scope: local
bookworm: resolved (fixed in 3.32.0-1)
bullseye: resolved (fixed in 3.32.0-1)
forky: resolved (fixed in 3.32.0-1)
sid: resolved (fixed in 3.32.0-1)
trixie: resolved (fixed in 3.32.0-1)
No detection rules found.
No public exploits indexed.
2022-09-01
Published