CVE-2020-9327
published 2020-02-21CVE-2020-9327: In SQLite 3.31.1, isAuxiliaryVtabOperator allows attackers to trigger a NULL pointer dereference and segmentation fault because of generated column…
high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
In SQLite 3.31.1, isAuxiliaryVtabOperator allows attackers to trigger a NULL pointer dereference and segmentation fault because of generated column optimizations.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | sqlite3 | < sqlite3 3.31.1-3 (bookworm) | sqlite3 3.31.1-3 (bookworm) |
| ghost | sqlite3 | >= 0 < 3.31.1-3 | 3.31.1-3 |
| ghost | sqlite3 | >= 0 < 3.31.1-3 | 3.31.1-3 |
| ghost | sqlite3 | >= 0 < 3.31.1-3 | 3.31.1-3 |
| ghost | sqlite3 | >= 0 < 3.31.1-3 | 3.31.1-3 |
| ghost | sqlite3 | >= 0 < 3.11.0-1ubuntu1.4 | 3.11.0-1ubuntu1.4 |
| ghost | sqlite3 | >= 0 < 3.22.0-1ubuntu0.3 | 3.22.0-1ubuntu0.3 |
| msrc | azl3_libdb_5.3.28-9_on_azure_linux_3.0 | — | — |
| oracle | communications_messaging_server | — | — |
| oracle | communications_network_charging_and_control | — | — |
| oracle | communications_network_charging_and_control | — | — |
| oracle | communications_network_charging_and_control | 12.0.0 – 12.0.3 | — |
| oracle | enterprise_manager_ops_center | — | — |
| oracle | hyperion_infrastructure_technology | — | — |
| oracle | mysql_workbench | <= 8.0.22 | — |
| oracle | outside_in_technology | — | — |
| oracle | outside_in_technology | — | — |
| oracle | zfs_storage_appliance_kit | — | — |
| siemens | sinec_infrastructure_network_services | < 1.0.1.1 | 1.0.1.1 |
| sqlite | sqlite | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH