cbcvebase.
CVE-2021-20227
published 2021-03-23

CVE-2021-20227: A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on the…

medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on the SQLite database to cause a denial of service or possible code execution by triggering a use-after-free. The highest threat from this vulnerability is to system availability.

Affected

22 ranges
VendorProductVersion rangeFixed in
debiansqlite3< sqlite3 3.34.1-1 (bookworm)sqlite3 3.34.1-1 (bookworm)
ghostsqlite3>= 0 < 3.34.1-13.34.1-1
ghostsqlite3>= 0 < 3.34.1-13.34.1-1
ghostsqlite3>= 0 < 3.34.1-13.34.1-1
ghostsqlite3>= 0 < 3.34.1-13.34.1-1
msrcsqlite-3.34.1-1.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm
msrcsqlite-3.34.1-1.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64
msrcsqlite-debuginfo-3.34.1-1.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm
msrcsqlite-debuginfo-3.34.1-1.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64
msrcsqlite-devel-3.34.1-1.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm
msrcsqlite-devel-3.34.1-1.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64
msrcsqlite-libs-3.34.1-1.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm
msrcsqlite-libs-3.34.1-1.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64
oraclecommunications_network_charging_and_control
oraclecommunications_network_charging_and_control12.0.1.0 – 12.0.4.0.0
oracleenterprise_manager_for_oracle_database
oraclejd_edwards_enterpriseone_tools< 9.2.6.09.2.6.0
oraclemysql_workbench<= 8.0.26
oracleoutside_in_technology
oraclezfs_storage_appliance_kit
sqlitesqlite
sqlitesqlite>= 3.33.0 < 3.34.13.34.1

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM