CVE-2021-36690
published 2021-08-24CVE-2021-36690: A segmentation fault can occur in the sqlite3.exe command-line component of SQLite 3.36.0 via the idxGetTableInfo function when there is a crafted SQL query…
PriorityP345high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.90%
89.1th percentile
A segmentation fault can occur in the sqlite3.exe command-line component of SQLite 3.36.0 via the idxGetTableInfo function when there is a crafted SQL query. NOTE: the vendor disputes the relevance of this report because a sqlite3.exe user already has full privileges (e.g., is intentionally allowed to execute commands). This report does NOT imply any problem in the SQLite library.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | iphone_os | < 16.0 | 16.0 |
| apple | macos | < 13.0 | 13.0 |
| apple | macos_ventura | — | — |
| apple | tvos | < 16.0 | 16.0 |
| apple | tvos | — | — |
| apple | watchos | < 9.0 | 9.0 |
| apple | watchos_9 | — | — |
| debian | sqlite3 | < sqlite3 3.36.0-2 (bookworm) | sqlite3 3.36.0-2 (bookworm) |
| ghost | sqlite3 | >= 0 < 3.34.1-3+deb11u1 | 3.34.1-3+deb11u1 |
| ghost | sqlite3 | >= 0 < 3.36.0-2 | 3.36.0-2 |
| ghost | sqlite3 | >= 0 < 3.36.0-2 | 3.36.0-2 |
| ghost | sqlite3 | >= 0 < 3.36.0-2 | 3.36.0-2 |
| msrc | cbl2_sqlite_3.36.0-3_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| oracle | zfs_storage_appliance_kit | — | — |
| sqlite | sqlite | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5LOW
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2021-36690: macOS Ventura 13
vendor_apple·2022-10-24·CVSS 7.5
CVE-2021-36690 [HIGH] CVE-2021-36690: macOS Ventura 13
Apple Security Update: About the security content of macOS Ventura 13
Product: macOS Ventura
Version: 13
CVE: CVE-2021-36690
Component: CVE-2021-36690
Apple
CVE-2021-36690: iOS 16
vendor_apple·2022-09-12·CVSS 7.5
CVE-2021-36690 [HIGH] CVE-2021-36690: iOS 16
Apple Security Update: About the security content of iOS 16
Product: iOS
Version: 16
CVE: CVE-2021-36690
Component: CVE-2021-36690
Apple
CVE-2021-36690: watchOS 9
vendor_apple·2022-09-12·CVSS 7.5
CVE-2021-36690 [HIGH] CVE-2021-36690: watchOS 9
Apple Security Update: About the security content of watchOS 9
Product: watchOS 9
CVE: CVE-2021-36690
Component: CVE-2021-36690
Apple
CVE-2021-36690: tvOS 16
vendor_apple·2022-09-12·CVSS 7.5
CVE-2021-36690 [HIGH] CVE-2021-36690: tvOS 16
Apple Security Update: About the security content of tvOS 16
Product: tvOS
Version: 16
CVE: CVE-2021-36690
Component: CVE-2021-36690
Ubuntu
SQLite vulnerability
vendor_ubuntu·2022-05-05
CVE-2021-36690 SQLite vulnerability
Title: SQLite vulnerability
Summary: SQLite could be made to crash or run programs if it processed a specially crafted query.
It was discovered that SQLite command-line component incorrectly handled
certain queries. An attacker could possibly use this issue to cause a
crash or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
A segmentation fault can occur in the sqlite3.exe command-line component of SQLite 3.36.0 via the idxGetTableInfo function when there is a crafted SQL query. NOTE: the vendor disputes the relevance of
vendor_msrc·2021-08-10·CVSS 7.5
CVE-2021-36690 [HIGH] A segmentation fault can occur in the sqlite3.exe command-line component of SQLite 3.36.0 via the idxGetTableInfo function when there is a crafted SQL query. NOTE: the vendor disputes the relevance of
A segmentation fault can occur in the sqlite3.exe command-line component of SQLite 3.36.0 via the idxGetTableInfo function when there is a crafted SQL query. NOTE: the vendor disputes the relevance of this report because a sqlite3.exe user already has full privileges (e.g. is intentionally allowed to execute commands). This report does NOT imply any problem in the SQLite library.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparen
Debian
CVE-2021-36690: sqlite3 - A segmentation fault can occur in the sqlite3.exe command-line component of SQLi...
vendor_debian·2021·CVSS 7.5
CVE-2021-36690 [HIGH] CVE-2021-36690: sqlite3 - A segmentation fault can occur in the sqlite3.exe command-line component of SQLi...
A segmentation fault can occur in the sqlite3.exe command-line component of SQLite 3.36.0 via the idxGetTableInfo function when there is a crafted SQL query. NOTE: the vendor disputes the relevance of this report because a sqlite3.exe user already has full privileges (e.g., is intentionally allowed to execute commands). This report does NOT imply any problem in the SQLite library.
Scope: local
bookworm: resolved (fixed in 3.36.0-2)
bullseye: resolved (fixed in 3.34.1-3+deb11u1)
forky: resolved (fixed in 3.36.0-2)
sid: resolved (fixed in 3.36.0-2)
trixie: resolved (fixed in 3.36.0-2)
GHSA
GHSA-j773-5h44-w4h6: Segmentation fault vulnerability in SQLite sqlite3 3
ghsa_unreviewed·2022-05-24
CVE-2021-36690 [HIGH] CWE-125 GHSA-j773-5h44-w4h6: Segmentation fault vulnerability in SQLite sqlite3 3
Segmentation fault vulnerability in SQLite sqlite3 3.36.0 via the idxGetTableInfo function, in which a crafted SQL query can cause a denial of service
OSV
CVE-2021-36690: A segmentation fault can occur in the sqlite3
osv·2021-08-24·CVSS 7.5
CVE-2021-36690 [HIGH] CVE-2021-36690: A segmentation fault can occur in the sqlite3
A segmentation fault can occur in the sqlite3.exe command-line component of SQLite 3.36.0 via the idxGetTableInfo function when there is a crafted SQL query. NOTE: the vendor disputes the relevance of this report because a sqlite3.exe user already has full privileges (e.g., is intentionally allowed to execute commands). This report does NOT imply any problem in the SQLite library.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://seclists.org/fulldisclosure/2022/Oct/28http://seclists.org/fulldisclosure/2022/Oct/39http://seclists.org/fulldisclosure/2022/Oct/41http://seclists.org/fulldisclosure/2022/Oct/47http://seclists.org/fulldisclosure/2022/Oct/49https://support.apple.com/kb/HT213446https://support.apple.com/kb/HT213486https://support.apple.com/kb/HT213487https://support.apple.com/kb/HT213488https://www.sqlite.org/forum/forumpost/718c0a8d17http://seclists.org/fulldisclosure/2022/Oct/28http://seclists.org/fulldisclosure/2022/Oct/39http://seclists.org/fulldisclosure/2022/Oct/41http://seclists.org/fulldisclosure/2022/Oct/47http://seclists.org/fulldisclosure/2022/Oct/49https://lists.debian.org/debian-lts-announce/2024/09/msg00050.htmlhttps://support.apple.com/kb/HT213446https://support.apple.com/kb/HT213486https://support.apple.com/kb/HT213487https://support.apple.com/kb/HT213488https://www.sqlite.org/forum/forumpost/718c0a8d17
2021-08-24
Published