CVE-2024-0232
published 2024-01-16CVE-2024-0232: A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a…
PriorityP419medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.34%
26.6th percentile
A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | sqlite3 | < sqlite3 3.43.2-1 (forky) | sqlite3 3.43.2-1 (forky) |
| fedoraproject | extra_packages_for_enterprise_linux | — | — |
| fedoraproject | fedora | — | — |
| ghost | sqlite3 | >= 0 < 3.43.2-1 | 3.43.2-1 |
| ghost | sqlite3 | >= 0 < 3.43.2-1 | 3.43.2-1 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| sqlite | sqlite | >= 3.43.0 < 3.43.2 | 3.43.2 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_oracle5.5MEDIUM
vendor_debian4.7LOW
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIDIS Prime
cisa_ics·2025-04-10
Siemens SIDIS Prime
ICS Advisory
##
Siemens SIDIS Prime
Release DateApril 10, 2025
Alert CodeICSA-25-100-02
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 9.1
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIDIS Prime
- Vulnerabilities: Race Condition Enabling Link Following, Improper Validation of Integrity Check Value, Unchecked Input for Loo
Oracle
Oracle Oracle Communications Applications Risk Matrix: Security (SQLite) — CVE-2024-0232
vendor_oracle·2025-01-15·CVSS 5.5
CVE-2024-0232 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Security (SQLite) — CVE-2024-0232
Oracle Oracle Communications Applications Risk Matrix: Security (SQLite) vulnerability
CVE: CVE-2024-0232
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujan2025 (JAN 2025)
CISA ICS
Siemens SINEC INS
cisa_ics·2024-11-14
Siemens SINEC INS
ICS Advisory
##
Siemens SINEC INS
Release DateNovember 14, 2024
Alert CodeICSA-24-319-08
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.9
- ATTENTION: Exploitable remotely/low attack complexity/public exploits are available/known public exploitation
- Vendor: Siemens
- Equipment: SINEC INS
- Vulnerabilities: Improper Authentication, Out-of-bounds Write, Ineffici
CISA ICS
Siemens RUGGEDCOM CROSSBOW
cisa_ics·2024-11-14·CVSS 5.5
[MEDIUM] Siemens RUGGEDCOM CROSSBOW
ICS Advisory
##
Siemens RUGGEDCOM CROSSBOW
Release DateNovember 14, 2024
Alert CodeICSA-24-319-01
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 5.5
- ATTENTION: Exploitable from adjacent network/low attack complexity
- Vendor: Siemens
- Equipment: RUGGEDCOM CROSSBOW
- Vulnerabilities: Heap-based Buffer Overflow, Use After Free
## 2. RISK EVALUATION
Successful e
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Reports (SQLite) — CVE-2024-0232
vendor_oracle·2024-10-15·CVSS 5.5
CVE-2024-0232 [MEDIUM] Oracle Oracle Financial Services Applications Risk Matrix: Reports (SQLite) — CVE-2024-0232
Oracle Oracle Financial Services Applications Risk Matrix: Reports (SQLite) vulnerability
CVE: CVE-2024-0232
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuoct2024 (OCT 2024)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Common fns (SQLite) — CVE-2024-0232
vendor_oracle·2024-07-15·CVSS 5.5
CVE-2024-0232 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Common fns (SQLite) — CVE-2024-0232
Oracle Oracle Communications Applications Risk Matrix: Common fns (SQLite) vulnerability
CVE: CVE-2024-0232
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2024 (JUL 2024)
Debian
CVE-2024-0232: sqlite3 - A heap use-after-free issue has been identified in SQLite in the jsonParseAddNod...
vendor_debian·2024·CVSS 4.7
CVE-2024-0232 [MEDIUM] CVE-2024-0232: sqlite3 - A heap use-after-free issue has been identified in SQLite in the jsonParseAddNod...
A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 3.43.2-1)
sid: resolved (fixed in 3.43.2-1)
trixie: resolved (fixed in 3.43.2-1)
Red Hat
sqlite: use-after-free bug in jsonParseAddNodeArray
vendor_redhat·2023-10-12·CVSS 4.7
CVE-2024-0232 [MEDIUM] CWE-416 sqlite: use-after-free bug in jsonParseAddNodeArray
sqlite: use-after-free bug in jsonParseAddNodeArray
A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service.
A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service.
Statement: Red Hat has determined this flaw to be of low impact as successful exploitation may result in a crash (denial of service) of the application and doe
GHSA
GHSA-3r49-2w65-cxgr: A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3
ghsa_unreviewed·2024-01-16
CVE-2024-0232 [MEDIUM] CWE-416 GHSA-3r49-2w65-cxgr: A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3
A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service.
OSV
CVE-2024-0232: A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3
osv·2024-01-16·CVSS 5.5
CVE-2024-0232 [MEDIUM] CVE-2024-0232: A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3
A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/security/cve/CVE-2024-0232https://bugzilla.redhat.com/show_bug.cgi?id=2243754https://access.redhat.com/security/cve/CVE-2024-0232https://bugzilla.redhat.com/show_bug.cgi?id=2243754https://lists.fedoraproject.org/archives/list/[email protected]/message/QDCMYQ3J45NHQ4EJREM3BJNNKB5BK4Y7/https://security.netapp.com/advisory/ntap-20240315-0007/
2024-01-16
Published