CVE-2021-20227
published 2021-03-23CVE-2021-20227: A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on the…
PriorityP424medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.50%
39.2th percentile
A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on the SQLite database to cause a denial of service or possible code execution by triggering a use-after-free. The highest threat from this vulnerability is to system availability.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | sqlite3 | < sqlite3 3.34.1-1 (bookworm) | sqlite3 3.34.1-1 (bookworm) |
| ghost | sqlite3 | >= 0 < 3.34.1-1 | 3.34.1-1 |
| ghost | sqlite3 | >= 0 < 3.34.1-1 | 3.34.1-1 |
| ghost | sqlite3 | >= 0 < 3.34.1-1 | 3.34.1-1 |
| ghost | sqlite3 | >= 0 < 3.34.1-1 | 3.34.1-1 |
| msrc | sqlite-3.34.1-1.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm | — | — |
| msrc | sqlite-3.34.1-1.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64 | — | — |
| msrc | sqlite-debuginfo-3.34.1-1.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm | — | — |
| msrc | sqlite-debuginfo-3.34.1-1.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64 | — | — |
| msrc | sqlite-devel-3.34.1-1.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm | — | — |
| msrc | sqlite-devel-3.34.1-1.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64 | — | — |
| msrc | sqlite-libs-3.34.1-1.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm | — | — |
| msrc | sqlite-libs-3.34.1-1.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64 | — | — |
| oracle | communications_network_charging_and_control | — | — |
| oracle | communications_network_charging_and_control | 12.0.1.0 – 12.0.4.0.0 | — |
| oracle | enterprise_manager_for_oracle_database | — | — |
| oracle | jd_edwards_enterpriseone_tools | < 9.2.6.0 | 9.2.6.0 |
| oracle | mysql_workbench | <= 8.0.26 | — |
| oracle | outside_in_technology | — | — |
| oracle | zfs_storage_appliance_kit | — | — |
| sqlite | sqlite | — | — |
| sqlite | sqlite | >= 3.33.0 < 3.34.1 | 3.34.1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_oracle5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Provisioning (SQLite) — CVE-2021-20227
vendor_oracle·2021-10-15·CVSS 5.5
CVE-2021-20227 [MEDIUM] Oracle Oracle Enterprise Manager Risk Matrix: Provisioning (SQLite) — CVE-2021-20227
Oracle Oracle Enterprise Manager Risk Matrix: Provisioning (SQLite) vulnerability
CVE: CVE-2021-20227
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuoct2021 (OCT 2021)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Common fns (SQLite) — CVE-2021-20227
vendor_oracle·2021-07-15·CVSS 5.5
CVE-2021-20227 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Common fns (SQLite) — CVE-2021-20227
Oracle Oracle Communications Applications Risk Matrix: Common fns (SQLite) vulnerability
CVE: CVE-2021-20227
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2021 (JUL 2021)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Installation (SQLite) — CVE-2021-20227
vendor_oracle·2021-04-15·CVSS 5.5
CVE-2021-20227 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: Installation (SQLite) — CVE-2021-20227
Oracle Oracle Fusion Middleware Risk Matrix: Installation (SQLite) vulnerability
CVE: CVE-2021-20227
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuapr2021 (APR 2021)
Microsoft
A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on the SQLite database to cause a denial of service o
vendor_msrc·2021-03-09·CVSS 5.5
CVE-2021-20227 [MEDIUM] CWE-416 A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on the SQLite database to cause a denial of service o
A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on the SQLite database to cause a denial of service or possible code execution by triggering a use-after-free. The highest threat from this vulnerability is to system availability.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/V
Ubuntu
SQLite vulnerability
vendor_ubuntu·2021-02-11
CVE-2021-20227 SQLite vulnerability
Title: SQLite vulnerability
Summary: SQLite could be made to crash or run programs if it processed a specially
crafted query.
It was discovered that SQLite incorrectly handled certain sub-queries. An
attacker could use this issue to cause SQLite to crash, resulting in a
denial of service, or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
sqlite: potential use-after-free bug when processing a subquery with both a correlated WHERE clause and a "HAVING 0" clause and where the parent query is an aggregate
vendor_redhat·2021-01-21·CVSS 5.5
CVE-2021-20227 [MEDIUM] CWE-416 sqlite: potential use-after-free bug when processing a subquery with both a correlated WHERE clause and a "HAVING 0" clause and where the parent query is an aggregate
sqlite: potential use-after-free bug when processing a subquery with both a correlated WHERE clause and a "HAVING 0" clause and where the parent query is an aggregate
A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on the SQLite database to cause a denial of service or possible code execution by triggering a use-after-free. The highest threat from this vulnerability is to system availability.
A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on the SQLite database to cause a denial of service or possible code execution by triggering a use-after-free. The highest threat from this vulnerability is
Debian
CVE-2021-20227: sqlite3 - A flaw was found in SQLite's SELECT query functionality (src/select.c). This fla...
vendor_debian·2021·CVSS 5.5
CVE-2021-20227 [MEDIUM] CVE-2021-20227: sqlite3 - A flaw was found in SQLite's SELECT query functionality (src/select.c). This fla...
A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on the SQLite database to cause a denial of service or possible code execution by triggering a use-after-free. The highest threat from this vulnerability is to system availability.
Scope: local
bookworm: resolved (fixed in 3.34.1-1)
bullseye: resolved (fixed in 3.34.1-1)
forky: resolved (fixed in 3.34.1-1)
sid: resolved (fixed in 3.34.1-1)
trixie: resolved (fixed in 3.34.1-1)
GHSA
GHSA-w586-cvch-p9ch: A flaw was found in SQLite's SELECT query functionality (src/select
ghsa_unreviewed·2022-05-24
CVE-2021-20227 [MEDIUM] CWE-416 GHSA-w586-cvch-p9ch: A flaw was found in SQLite's SELECT query functionality (src/select
A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on the SQLite database to cause a denial of service or possible code execution by triggering a use-after-free. The highest threat from this vulnerability is to system availability.
OSV
CVE-2021-20227: A flaw was found in SQLite's SELECT query functionality (src/select
osv·2021-03-23·CVSS 5.5
CVE-2021-20227 [MEDIUM] CVE-2021-20227: A flaw was found in SQLite's SELECT query functionality (src/select
A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on the SQLite database to cause a denial of service or possible code execution by triggering a use-after-free. The highest threat from this vulnerability is to system availability.
No detection rules found.
No public exploits indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1924886https://security.gentoo.org/glsa/202103-04https://security.gentoo.org/glsa/202210-40https://security.netapp.com/advisory/ntap-20210423-0010/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://www.sqlite.org/releaselog/3_34_1.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1924886https://security.gentoo.org/glsa/202103-04https://security.gentoo.org/glsa/202210-40https://security.netapp.com/advisory/ntap-20210423-0010/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://www.sqlite.org/releaselog/3_34_1.html
2021-03-23
Published