CVE-2025-3277
published 2025-04-14CVE-2025-3277: An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used to allocate a buffer. When SQLite then…
PriorityP355critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.77%
51.5th percentile
An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used to allocate a buffer. When SQLite then writes the resulting string to the buffer, it uses the original, untruncated size and thus a wild Heap Buffer overflow of size ~4GB can be triggered. This can result in arbitrary code execution.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | sqlite3 | < sqlite3 3.46.1-3 (forky) | sqlite3 3.46.1-3 (forky) |
| ghost | sqlite3 | >= 0 < 3.46.1-3 | 3.46.1-3 |
| ghost | sqlite3 | >= 0 < 3.46.1-3 | 3.46.1-3 |
| ghost | sqlite3 | >= 0 < 3.31.1-4ubuntu0.7 | 3.31.1-4ubuntu0.7 |
| ghost | sqlite3 | >= 0 < 3.37.2-2ubuntu0.4 | 3.37.2-2ubuntu0.4 |
| ghost | sqlite3 | >= 0 < 3.45.1-1ubuntu2.3 | 3.45.1-1ubuntu2.3 |
| msrc | azl3_libdb_5.3.28-9_on_azure_linux_3.0 | — | — |
| msrc | azl3_sqlite_3.44.0-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_libdb_5.3.28-7_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_sqlite_3.39.2-3_on_cbl_mariner_2.0 | — | — |
| sqlite | sqlite | < 3.49.1 | 3.49.1 |
| sqlite | sqlite | >= 3.44.0 < 3.49.1 | 3.49.1 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv7.5HIGH
vendor_msrc9.8CRITICAL
vendor_debian6.9LOW
vendor_redhat6.9MEDIUM
vendor_ubuntu3.2LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens RUGGEDCOM CROSSBOW Station Access Controller
cisa_ics·2025-08-14·CVSS 9.8
[CRITICAL] Siemens RUGGEDCOM CROSSBOW Station Access Controller
ICS Advisory
##
Siemens RUGGEDCOM CROSSBOW Station Access Controller
Release DateAugust 14, 2025
Alert CodeICSA-25-226-08
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 6.9
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: RUGGEDCOM CROSSBOW Station Access Controller (SAC)
- Vulnerabilities: Heap-Based Buffer Overflow, Integer
Ubuntu
SQLite vulnerabilities
vendor_ubuntu·2025-05-22·CVSS 3.2
CVE-2025-29088 [LOW] SQLite vulnerabilities
Title: SQLite vulnerabilities
Summary: Several security issues were fixed in SQLite.
It was discovered that SQLite incorrectly handled the concat_ws() function.
An attacker could use this issue to cause SQLite to crash, resulting in a
denial of service, or possibly execute arbitrary code. This issue only
affected Ubuntu 24.04 LTS, and Ubuntu 24.10. (CVE-2025-29087,
CVE-2025-3277)
It was discovered that SQLite incorrectly handled certain argument values
to sqlite3_db_config(). An attacker could use this issue to cause SQLite to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2025-29088)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
SQLite: integer overflow in SQLite
vendor_redhat·2025-04-14·CVSS 6.9
CVE-2025-3277 [MEDIUM] CWE-122 SQLite: integer overflow in SQLite
SQLite: integer overflow in SQLite
An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used to allocate a buffer. When SQLite then writes the resulting string to the buffer, it uses the original, untruncated size and thus a wild Heap Buffer overflow of size ~4GB can be triggered. This can result in arbitrary code execution.
A flaw was found in SQLite’s `concat_ws()` function, where an integer overflow can be triggered. The resulting truncated integer can allocate a buffer. When SQLite writes the resulting string to the buffer, it uses the original, untruncated size, and a wild heap buffer overflow size of around 4GB can occur. This issue can result in arbitrary code execution.
Statement: For Openshift, the bundled sqlite3.c d
Microsoft
An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used to allocate a buffer. When SQLite then writes the resulting string to the buffer,
vendor_msrc·2025-04-08·CVSS 9.8
CVE-2025-3277 [MEDIUM] CWE-122 An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used to allocate a buffer. When SQLite then writes the resulting string to the buffer,
An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used to allocate a buffer. When SQLite then writes the resulting string to the buffer, it uses the original, untruncated size and thus a wild Heap Buffer overflow of size ~4GB can be triggered. This can result in arbitrary code execution.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why w
Debian
CVE-2025-3277: sqlite3 - An integer overflow can be triggered in SQLite’s `concat_ws()` function. The res...
vendor_debian·2025·CVSS 6.9
CVE-2025-3277 [MEDIUM] CVE-2025-3277: sqlite3 - An integer overflow can be triggered in SQLite’s `concat_ws()` function. The res...
An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used to allocate a buffer. When SQLite then writes the resulting string to the buffer, it uses the original, untruncated size and thus a wild Heap Buffer overflow of size ~4GB can be triggered. This can result in arbitrary code execution.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 3.46.1-3)
sid: resolved (fixed in 3.46.1-3)
trixie: resolved (fixed in 3.46.1-3)
OSV
sqlite3 vulnerabilities
osv·2025-05-22·CVSS 7.5
CVE-2025-29087 [HIGH] sqlite3 vulnerabilities
sqlite3 vulnerabilities
It was discovered that SQLite incorrectly handled the concat_ws() function.
An attacker could use this issue to cause SQLite to crash, resulting in a
denial of service, or possibly execute arbitrary code. This issue only
affected Ubuntu 24.04 LTS, and Ubuntu 24.10. (CVE-2025-29087,
CVE-2025-3277)
It was discovered that SQLite incorrectly handled certain argument values
to sqlite3_db_config(). An attacker could use this issue to cause SQLite to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2025-29088)
OSV
CVE-2025-3277: An integer overflow can be triggered in SQLite’s `concat_ws()` function
osv·2025-04-14·CVSS 6.9
CVE-2025-3277 [MEDIUM] CVE-2025-3277: An integer overflow can be triggered in SQLite’s `concat_ws()` function
An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used to allocate a buffer. When SQLite then writes the resulting string to the buffer, it uses the original, untruncated size and thus a wild Heap Buffer overflow of size ~4GB can be triggered. This can result in arbitrary code execution.
GHSA
GHSA-g2ph-wvc2-ph4v: An integer overflow can be triggered in SQLite’s `concat_ws()` function
ghsa_unreviewed·2025-04-14
CVE-2025-3277 [MEDIUM] CWE-122 GHSA-g2ph-wvc2-ph4v: An integer overflow can be triggered in SQLite’s `concat_ws()` function
An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used to allocate a buffer. When SQLite then writes the resulting string to the buffer, it uses the original, untruncated size and thus a wild Heap Buffer overflow of size ~4GB can be triggered. This can result in arbitrary code execution.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-04-14
Published