CVE-2022-35737
published 2022-08-03CVE-2022-35737: SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.
PriorityP349high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
17.98%
96.9th percentile
SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | sqlite3 | < sqlite3 3.39.2-1 (bookworm) | sqlite3 3.39.2-1 (bookworm) |
| ghost | sqlite3 | >= 0 < 3.39.2-1 | 3.39.2-1 |
| ghost | sqlite3 | >= 0 < 3.39.2-1 | 3.39.2-1 |
| ghost | sqlite3 | >= 0 < 3.39.2-1 | 3.39.2-1 |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | windows_10_version_1809_for_32-bit_systems | — | — |
| msrc | windows_10_version_1809_for_arm64-based_systems | — | — |
| msrc | windows_10_version_1809_for_x64-based_systems | — | — |
| msrc | windows_10_version_21h2_for_32-bit_systems | — | — |
| msrc | windows_10_version_21h2_for_arm64-based_systems | — | — |
| msrc | windows_10_version_21h2_for_x64-based_systems | — | — |
| msrc | windows_10_version_22h2_for_32-bit_systems | — | — |
| msrc | windows_10_version_22h2_for_arm64-based_systems | — | — |
| msrc | windows_10_version_22h2_for_x64-based_systems | — | — |
| msrc | windows_server_2019 | — | — |
| msrc | windows_server_2022 | — | — |
| splunk | universal_forwarder | — | — |
| splunk | universal_forwarder | >= 8.2.0 < 8.2.12 | 8.2.12 |
| splunk | universal_forwarder | >= 9.0.0 < 9.0.6 | 9.0.6 |
| sqlite | sqlite | >= 1.0.12 < 3.39.2 | 3.39.2 |
Detection & IOCsextracted from sources · hover to see the quote
bytes↗
src[0] = '\xc0'; memset(src+1, '\x80', 0xffffffff)
- ·Arbitrary code execution is only confirmed when SQLite is compiled WITHOUT stack canaries. When stack canaries are present, only denial-of-service (crash) is confirmed. Assess the build configuration of the target SQLite library before estimating impact. ↗
- ·The vulnerability was fixed in SQLite 3.39.2 (released July 21, 2022). Versions 1.0.12 through 3.39.1 are affected. Confirm the exact linked/bundled SQLite version in the application, as many applications ship their own copy. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5LOW
vendor_msrc7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
MITRE: CVE-2022-35737 SQLite allows an array-bounds overflow
vendor_msrc·2024-01-09·CVSS 7.5
CVE-2022-35737 [HIGH] MITRE: CVE-2022-35737 SQLite allows an array-bounds overflow
MITRE: CVE-2022-35737 SQLite allows an array-bounds overflow
NIST NVD Details: https://nvd.nist.gov/vuln/detail/CVE-2022-35737
FAQ: Why is the MITRE Corporation the assigning CNA (CVE Numbering Authority)?
CVE-2022-35737 is regarding a vulnerability in SQLite. MITRE assigned this CVE number on behalf of the SQLite organization. Microsoft has included the updated library in Windows that addresses this vulnerability.
SQLite: SQLite
MITRE Corporation: MITRE Corporation
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;DOS:N/A
Remediation: sqlite
Reference: https://nvd.nist.gov/vuln/detail/CVE-2022-35737
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB
Oracle
Oracle Oracle Communications Risk Matrix: Policy (SQLite) — CVE-2022-35737
vendor_oracle·2023-04-15·CVSS 7.5
CVE-2022-35737 [HIGH] Oracle Oracle Communications Risk Matrix: Policy (SQLite) — CVE-2022-35737
Oracle Oracle Communications Risk Matrix: Policy (SQLite) vulnerability
CVE: CVE-2022-35737
CVSS: 7.5
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Oracle
Oracle Oracle Communications Applications Risk Matrix: IMAP (NSS) — CVE-2022-35737
vendor_oracle·2023-01-15·CVSS 7.5
CVE-2022-35737 [HIGH] Oracle Oracle Communications Applications Risk Matrix: IMAP (NSS) — CVE-2022-35737
Oracle Oracle Communications Applications Risk Matrix: IMAP (NSS) vulnerability
CVE: CVE-2022-35737
CVSS: 7.5
Protocol: TLS
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
Ubuntu
SQLite vulnerability
vendor_ubuntu·2022-11-21
CVE-2022-35737 SQLite vulnerability
Title: SQLite vulnerability
Summary: SQLite could be made to crash or run programs if it received specially
crafted input.
USN-5716-1 fixed a vulnerability in SQLite. This update provides
the corresponding update for Ubuntu 14.04 ESM.
Original advisory details:
It was discovered that SQLite incorrectly handled certain long string
arguments. An attacker could use this issue to cause SQLite to crash,
resulting in a denial of service, or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
SQLite vulnerability
vendor_ubuntu·2022-11-07
CVE-2022-35737 SQLite vulnerability
Title: SQLite vulnerability
Summary: SQLite could be made to crash or run programs if it received specially
crafted input.
It was discovered that SQLite incorrectly handled certain long string
arguments. An attacker could use this issue to cause SQLite to crash,
resulting in a denial of service, or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
SQLite vulnerability
vendor_ubuntu·2022-11-03
CVE-2022-35737 SQLite vulnerability
Title: SQLite vulnerability
Summary: SQLite could be made to crash or run programs as your login if it
received specially crafted input.
It was discovered that SQLite did not properly handle large string
inputs in certain circumstances. An attacker could possibly use this
issue to cause a denial of service or arbitrary code execution.
Instructions: In general, a standard system update will make all the necessary changes.
Oracle
Oracle Oracle Communications Applications Risk Matrix: Common (SQLite) — CVE-2022-35737
vendor_oracle·2022-10-15·CVSS 7.5
CVE-2022-35737 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Common (SQLite) — CVE-2022-35737
Oracle Oracle Communications Applications Risk Matrix: Common (SQLite) vulnerability
CVE: CVE-2022-35737
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Red Hat
sqlite: an array-bounds overflow if billions of bytes are used in a string argument to a C API
vendor_redhat·2022-07-22·CVSS 7.5
CVE-2022-35737 [HIGH] CWE-129 sqlite: an array-bounds overflow if billions of bytes are used in a string argument to a C API
sqlite: an array-bounds overflow if billions of bytes are used in a string argument to a C API
SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.
An array-bounds overflow vulnerability was discovered in SQLite. The vulnerability occurs when handling an overly large input passed as a string argument to some of the C-language APIs provided by SQLite. This flaw allows a remote attacker to pass specially crafted large input to the application and perform a denial of service (DoS) attack.
Package: sqlite (Red Hat Enterprise Linux 7) - Out of support scope
Debian
CVE-2022-35737: sqlite3 - SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds over...
vendor_debian·2022·CVSS 7.5
CVE-2022-35737 [HIGH] CVE-2022-35737: sqlite3 - SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds over...
SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.
Scope: local
bookworm: resolved (fixed in 3.39.2-1)
bullseye: open
forky: resolved (fixed in 3.39.2-1)
sid: resolved (fixed in 3.39.2-1)
trixie: resolved (fixed in 3.39.2-1)
OSV
`libsqlite3-sys` via C SQLite improperly validates array index
osv·2022-08-04
CVE-2022-35737 [HIGH] `libsqlite3-sys` via C SQLite improperly validates array index
`libsqlite3-sys` via C SQLite improperly validates array index
SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.
GHSA
`libsqlite3-sys` via C SQLite improperly validates array index
ghsa·2022-08-04
CVE-2022-35737 [HIGH] CWE-129 `libsqlite3-sys` via C SQLite improperly validates array index
`libsqlite3-sys` via C SQLite improperly validates array index
SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.
OSV
`libsqlite3-sys` via C SQLite CVE-2022-35737
osv·2022-08-03·CVSS 7.5
CVE-2022-35737 [HIGH] `libsqlite3-sys` via C SQLite CVE-2022-35737
`libsqlite3-sys` via C SQLite CVE-2022-35737
It was sometimes possible for SQLite versions >= 1.0.12, < 3.39.2 to allow an array-bounds overflow when large string were input into SQLite's `printf` function.
As `libsqlite3-sys` bundles SQLite, it is susceptible to the vulnerability. `libsqlite3-sys` was updated to bundle the patched version of SQLite [here](https://github.com/rusqlite/rusqlite/releases/tag/sys0.25.1).
OSV
CVE-2022-35737: SQLite 1
osv·2022-08-03·CVSS 7.5
CVE-2022-35737 [HIGH] CVE-2022-35737: SQLite 1
SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.
No detection rules found.
No public exploits indexed.
Trendmicro
The January 2024 Security Update Review
blogs_trendmicro·2024-01-09·CVSS 8.8
[HIGH] The January 2024 Security Update Review
# The January 2024 Security Update Review
Get the January 2024 security update and review.
By: Dustin Childs
2024/01/09
Read time: ( words)
Save to Folio
Welcome to the first patch Tuesday of 2024. As expected, Microsoft and Adobe have released their latest security patches. Take a break from your other activities and join us as we review the details of their latest advisories. If you’d rather watch the video recap, you can check it out here:
Adobe Patches for January 2024
For January, Adobe released a single patch addressing six CVEs in Substance 3D Stager. All six bugs are rated Important with the most severe allowing arbitrary code execution.
None of the bugs fixed by Adobe this month are listed as publicly known or under active attack at the time of release. Adobe categorizes t
Trendmicro
The January 2024 Security Update Review
blogs_trendmicro·2024-01-09·CVSS 9.1
[CRITICAL] The January 2024 Security Update Review
## The January 2024 Security Update Review
Get the January 2024 security update and review.
By: Dustin Childs Jan 09, 2024 Read time: ( words)
Save to Folio
Welcome to the first patch Tuesday of 2024. As expected, Microsoft and Adobe have released their latest security patches. Take a break from your other activities and join us as we review the details of their latest advisories. If you’d rather watch the video recap, you can check it out here:
CVE
Title
Severity
CVSS
Public
Exploited
Type
CVE-2024-20700
Windows Hyper-V Remote Code Execution Vulnerability
Critical
7.5
No
No
RCE
CVE-2024-20674
Windows Kerberos Security Feature Bypass Vulnerability
Critical
9
No
No
SFB
CVE-2024-0057
.NET and Visual Studio Framework Security Feature Bypass Vulnerability
Important
Trendmicro
The January 2024 Security Update Review
blogs_trendmicro·2024-01-09·CVSS 9.1
[CRITICAL] The January 2024 Security Update Review
## The January 2024 Security Update Review
Get the January 2024 security update and review.
By: Dustin Childs 2024/01/09 Read time: ( words)
Save to Folio
Welcome to the first patch Tuesday of 2024. As expected, Microsoft and Adobe have released their latest security patches. Take a break from your other activities and join us as we review the details of their latest advisories. If you’d rather watch the video recap, you can check it out here:
CVE
Title
Severity
CVSS
Public
Exploited
Type
CVE-2024-20700
Windows Hyper-V Remote Code Execution Vulnerability
Critical
7.5
No
No
RCE
CVE-2024-20674
Windows Kerberos Security Feature Bypass Vulnerability
Critical
9
No
No
SFB
CVE-2024-0057
.NET and Visual Studio Framework Security Feature Bypass Vulnerability
Important
8
Bleepingcomputer
Microsoft January 2024 Patch Tuesday fixes 49 flaws, 12 RCE bugs
blogs_bleepingcomputer·2024-01-09·CVSS 8.8
[HIGH] Microsoft January 2024 Patch Tuesday fixes 49 flaws, 12 RCE bugs
## Microsoft January 2024 Patch Tuesday fixes 49 flaws, 12 RCE bugs
## Lawrence Abrams
10 Elevation of Privilege Vulnerabilities
7 Security Feature Bypass Vulnerabilities
12 Remote Code Execution Vulnerabilities
11 Information Disclosure Vulnerabilities
6 Denial of Service Vulnerabilities
3 Spoofing Vulnerabilities
The total count of 49 flaws does not include 4 Microsoft Edge flaws fixed on January 5th.
To learn more about the non-security updates released today, you can review our dedicated articles on the new Windows 11 KB5034123 cumulative update and Windows 10 KB5034122 update .
## This month's interesting flaws
While there were no actively exploited or publicly disclosed vulnerabilities this month, some flaws are more interesting than others.
Microsoft fixes an Office Remo
Trendmicro
The January 2024 Security Update Review
blogs_trendmicro·2024-01-09·CVSS 9.1
[CRITICAL] The January 2024 Security Update Review
## The January 2024 Security Update Review
Get the January 2024 security update and review.
By: Dustin Childs Jan 09, 2024 Read time: ( words)
Save to Folio
Welcome to the first patch Tuesday of 2024. As expected, Microsoft and Adobe have released their latest security patches. Take a break from your other activities and join us as we review the details of their latest advisories. If you’d rather watch the video recap, you can check it out here:
CVE
Title
Severity
CVSS
Public
Exploited
Type
CVE-2024-20700
Windows Hyper-V Remote Code Execution Vulnerability
Critical
7.5
No
No
RCE
CVE-2024-20674
Windows Kerberos Security Feature Bypass Vulnerability
Critical
9
No
No
SFB
CVE-2024-0057
.NET and Visual Studio Framework Security Feature Bypass Vulnerability
Important
Tenable
Microsoft’s January 2024 Patch Tuesday Addresses 48 CVEs (CVE-2024-20674)
blogs_tenable·2024-01-09·CVSS 8.8
[HIGH] Microsoft’s January 2024 Patch Tuesday Addresses 48 CVEs (CVE-2024-20674)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Trailofbits
Stranger Strings: An exploitable flaw in SQLite
blogs_trailofbits·2022-10-25·CVSS 7.5
CVE-2022-35737 [HIGH] Stranger Strings: An exploitable flaw in SQLite
Trail of Bits is publicly disclosing CVE-2022-35737, which affects applications that use the SQLite library API. CVE-2022-35737 was introduced in SQLite version 1.0.12 (released on October 17, 2000) and fixed in release 3.39.2 (released on July 21, 2022). CVE-2022-35737 is exploitable on 64-bit systems, and exploitability depends on how the program is compiled; arbitrary code execution is confirmed when the library is compiled without stack canaries, but unconfirmed when stack canaries are present, and denial-of-service is confirmed in all cases.
On vulnerable systems, CVE-2022-35737 is exploitable when large string inputs are passed to the SQLite implementations of the `printf` functions and when the format string contains the `%Q`, `%q`, or `%w` format substitution types. This is enough
Trailofbits
Stranger Strings: An exploitable flaw in SQLite
blogs_trailofbits·2022-10-25·CVSS 7.5
CVE-2022-35737 [HIGH] Stranger Strings: An exploitable flaw in SQLite
Trail of Bits is publicly disclosing CVE-2022-35737 , which affects applications that use the SQLite library API. CVE-2022-35737 was introduced in SQLite version 1.0.12 (released on October 17, 2000) and fixed in release 3.39.2 (released on July 21, 2022). CVE-2022-35737 is exploitable on 64-bit systems, and exploitability depends on how the program is compiled; arbitrary code execution is confirmed when the library is compiled without stack canaries, but unconfirmed when stack canaries are present, and denial-of-service is confirmed in all cases.
printf
%Q
%q
%w
!
SQLite is used in nearly everything , from naval warships to smartphones to other programming languages. The open-source database engine has a long history of being very secure: many CVEs that are initially pinned to SQLit
https://blog.trailofbits.com/2022/10/25/sqlite-vulnerability-july-2022-library-api/https://kb.cert.org/vuls/id/720344https://security.gentoo.org/glsa/202210-40https://security.netapp.com/advisory/ntap-20220915-0009/https://sqlite.org/releaselog/3_39_2.htmlhttps://www.sqlite.org/cves.htmlhttps://blog.trailofbits.com/2022/10/25/sqlite-vulnerability-july-2022-library-api/https://kb.cert.org/vuls/id/720344https://security.gentoo.org/glsa/202210-40https://security.netapp.com/advisory/ntap-20220915-0009/https://sqlite.org/releaselog/3_39_2.htmlhttps://www.sqlite.org/cves.html
2022-08-03
Published