CVE-2018-20506
SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attackers to…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (7.56%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases). This is a different vulnerability than CVE-2018-20346.
- CVSS 3.0
- 8.1 HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 7.56% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-190
- Affected
- sqlite/sqlite · apple/iphone os · apple/mac os x · apple/tvos · apple/watchos · apple/icloud · apple/itunes · opensuse/leap
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00070.htmlMailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2019/Jan/62Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2019/Jan/64Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2019/Jan/66Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2019/Jan/67Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2019/Jan/68Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2019/Jan/69Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/106698Third Party Advisory, VDB Entry
- https://kc.mcafee.com/corporate/index?page=content&id=SB10365
- https://lists.debian.org/debian-lts-announce/2020/08/msg00037.html
- https://seclists.org/bugtraq/2019/Jan/28Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Jan/29Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Jan/31Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Jan/32Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Jan/33Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Jan/39Mailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20190502-0004/Third Party Advisory
- https://sqlite.org/src/info/940f2adc8541a838Vendor Advisory
- https://support.apple.com/kb/HT209443Third Party Advisory
- https://support.apple.com/kb/HT209446Third Party Advisory
- https://support.apple.com/kb/HT209447Third Party Advisory
- https://support.apple.com/kb/HT209448Third Party Advisory
- https://support.apple.com/kb/HT209450Third Party Advisory
- https://support.apple.com/kb/HT209451Third Party Advisory
- https://usn.ubuntu.com/4019-1/
- https://usn.ubuntu.com/4019-2/
- https://www.oracle.com/security-alerts/cpuapr2020.html
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00070.htmlMailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2019/Jan/62Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2019/Jan/64Mailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.