cbcvebase.
CVE-2024-0232
published 2024-01-16

CVE-2024-0232: A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a…

medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service.

Affected

8 ranges
VendorProductVersion rangeFixed in
debiansqlite3< sqlite3 3.43.2-1 (forky)sqlite3 3.43.2-1 (forky)
fedoraprojectextra_packages_for_enterprise_linux
fedoraprojectfedora
ghostsqlite3>= 0 < 3.43.2-13.43.2-1
ghostsqlite3>= 0 < 3.43.2-13.43.2-1
redhatenterprise_linux
redhatenterprise_linux
sqlitesqlite>= 3.43.0 < 3.43.23.43.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv5.5MEDIUM