CVE-2020-35527
published 2022-09-01CVE-2020-35527: In SQLite 3.31.1, there is an out of bounds access problem through ALTER TABLE for views that have a nested FROM clause.
PriorityP343critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.07%
61.1th percentile
In SQLite 3.31.1, there is an out of bounds access problem through ALTER TABLE for views that have a nested FROM clause.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | sqlite3 | < sqlite3 3.32.0-1 (bookworm) | sqlite3 3.32.0-1 (bookworm) |
| ghost | sqlite3 | >= 0 < 3.32.0-1 | 3.32.0-1 |
| ghost | sqlite3 | >= 0 < 3.32.0-1 | 3.32.0-1 |
| ghost | sqlite3 | >= 0 < 3.32.0-1 | 3.32.0-1 |
| ghost | sqlite3 | >= 0 < 3.32.0-1 | 3.32.0-1 |
| ghost | sqlite3 | >= 0 < 3.22.0-1ubuntu0.6 | 3.22.0-1ubuntu0.6 |
| ghost | sqlite3 | >= 0 < 3.31.1-4ubuntu0.4 | 3.31.1-4ubuntu0.4 |
| ghost | sqlite3 | >= 0 < 3.8.2-1ubuntu2.2+esm4 | 3.8.2-1ubuntu2.2+esm4 |
| paloalto | pan-os | — | — |
| sqlite | sqlite | — | — |
| sqlite | sqlite | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
SQLite vulnerability
vendor_ubuntu·2024-06-27·CVSS 7.5
CVE-2020-35525 [HIGH] SQLite vulnerability
Title: SQLite vulnerability
Summary: SQLite could be made to crash or execute arbitrary code.
USN-5615-1 fixed several vulnerabilities in SQLite. This update provides
the corresponding fix for CVE-2020-35525 for Ubuntu 14.04 LTS.
Original advisory details:
It was discovered that SQLite incorrectly handled INTERSEC query
processing. An attacker could use this issue to cause SQLite to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2020-35525)
It was discovered that SQLite incorrectly handled ALTER TABLE for views
that have a nested FROM clause. An attacker could use this issue to cause
SQLite to crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue was only addressed in Ubuntu 20.04 LTS.
(CVE-2020-35527)
It was discov
Palo Alto
PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS
vendor_paloalto·2024-04-10·CVSS 9.8
CVE-2015-5739 [CRITICAL] PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS
PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS. While it was not determined that these CVEs have any significant impact on PAN-OS, they have been fixed out of an abundance of caution. CVE Summary CVE-2015-5739 This CVE is fixed in PAN-OS 11.0.4, and all later PAN-OS versions. CVE-2016-10228 This CVE is fixed in PAN-OS 11.1.3, and all later PAN-OS versions. CVE-2017-8923 This CVE is fixed in PAN-OS 10.2.8, 11.0.3, and all later PAN-OS versions. CVE-2017-9120 This CVE is fixed in PAN-OS 10.2.8, 11.0.3, and all later PAN-OS versions. CVE-2018-25009 This CVE is fixed in PAN-OS 10.2.8, 11.0.4, 11.1.3, and all later PAN-OS versions. CVE-2
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
Ubuntu
SQLite vulnerabilities
vendor_ubuntu·2022-09-15·CVSS 7.5
CVE-2021-20223 [HIGH] SQLite vulnerabilities
Title: SQLite vulnerabilities
Summary: Several security issues were fixed in SQLite.
It was discovered that SQLite incorrectly handled INTERSEC query
processing. An attacker could use this issue to cause SQLite to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2020-35525)
It was discovered that SQLite incorrectly handled ALTER TABLE for views
that have a nested FROM clause. An attacker could use this issue to cause
SQLite to crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue was only addressed in Ubuntu 20.04 LTS.
(CVE-2020-35527)
It was discovered that SQLite incorrectly handled embedded null characters
when tokenizing certain unicode strings. This issue could result in
incorrect results. This issue only affected
Red Hat
sqlite: Out of bounds access during table rename
vendor_redhat·2020-02-23·CVSS 9.8
CVE-2020-35527 [CRITICAL] CWE-119 sqlite: Out of bounds access during table rename
sqlite: Out of bounds access during table rename
In SQLite 3.31.1, there is an out of bounds access problem through ALTER TABLE for views that have a nested FROM clause.
An out-of-bounds read vulnerability was found in SQLite. This security flaw occurs when the ALTER TABLE for views has a nested FROM clause. This flaw allows an attacker to triage an out-of-bounds read and access confidential data successfully.
Package: sqlite (Red Hat Enterprise Linux 6) - Out of support scope
Package: sqlite (Red Hat Enterprise Linux 7) - Out of support scope
Package: sqlite (Red Hat Enterprise Linux 9) - Not affected
Debian
CVE-2020-35527: sqlite3 - In SQLite 3.31.1, there is an out of bounds access problem through ALTER TABLE f...
vendor_debian·2020·CVSS 9.8
CVE-2020-35527 [CRITICAL] CVE-2020-35527: sqlite3 - In SQLite 3.31.1, there is an out of bounds access problem through ALTER TABLE f...
In SQLite 3.31.1, there is an out of bounds access problem through ALTER TABLE for views that have a nested FROM clause.
Scope: local
bookworm: resolved (fixed in 3.32.0-1)
bullseye: resolved (fixed in 3.32.0-1)
forky: resolved (fixed in 3.32.0-1)
sid: resolved (fixed in 3.32.0-1)
trixie: resolved (fixed in 3.32.0-1)
OSV
sqlite3 vulnerability
osv·2024-06-27·CVSS 7.5
CVE-2020-35525 [HIGH] sqlite3 vulnerability
sqlite3 vulnerability
USN-5615-1 fixed several vulnerabilities in SQLite. This update provides
the corresponding fix for CVE-2020-35525 for Ubuntu 14.04 LTS.
Original advisory details:
It was discovered that SQLite incorrectly handled INTERSEC query
processing. An attacker could use this issue to cause SQLite to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2020-35525)
It was discovered that SQLite incorrectly handled ALTER TABLE for views
that have a nested FROM clause. An attacker could use this issue to cause
SQLite to crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue was only addressed in Ubuntu 20.04 LTS.
(CVE-2020-35527)
It was discovered that SQLite incorrectly handled embedded null characters
when tokeni
OSV
sqlite3 vulnerabilities
osv·2022-09-15·CVSS 7.5
CVE-2020-35525 [HIGH] sqlite3 vulnerabilities
sqlite3 vulnerabilities
It was discovered that SQLite incorrectly handled INTERSEC query
processing. An attacker could use this issue to cause SQLite to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2020-35525)
It was discovered that SQLite incorrectly handled ALTER TABLE for views
that have a nested FROM clause. An attacker could use this issue to cause
SQLite to crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue was only addressed in Ubuntu 20.04 LTS.
(CVE-2020-35527)
It was discovered that SQLite incorrectly handled embedded null characters
when tokenizing certain unicode strings. This issue could result in
incorrect results. This issue only affected Ubuntu 20.04 LTS.
(CVE-2021-20223)
GHSA
GHSA-c76x-fv7r-4xjr: In SQLite 3
ghsa_unreviewed·2022-09-02
CVE-2020-35527 [CRITICAL] CWE-119 GHSA-c76x-fv7r-4xjr: In SQLite 3
In SQLite 3.31.1, there is an out of bounds access problem through ALTER TABLE for views that have a nested FROM clause.
OSV
CVE-2020-35527: In SQLite 3
osv·2022-09-01·CVSS 9.8
CVE-2020-35527 [CRITICAL] CVE-2020-35527: In SQLite 3
In SQLite 3.31.1, there is an out of bounds access problem through ALTER TABLE for views that have a nested FROM clause.
No detection rules found.
No public exploits indexed.
2022-09-01
Published