VulnerabilityModified
CVE-2019-19880
exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values in ORDER BY clauses of window definitions are mishandled.
HIGH 7.5EPSS 6.94%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (6.94%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values in ORDER BY clauses of window definitions are mishandled.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 6.94% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-476
- Affected
- sqlite/sqlite · netapp/cloud backup · debian/debian linux · suse/package hub · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux workstation · opensuse/backports sle · opensuse/leap · oracle/mysql workbench · siemens/sinec infrastructure network services
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00010.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00015.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00025.htmlMailing List, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0514Third Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdfPatch, Third Party Advisory
- https://github.com/sqlite/sqlite/commit/75e95e1fcd52d3ec8282edb75ac8cd0814095d54Patch, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20200114-0001/Third Party Advisory
- https://usn.ubuntu.com/4298-1/Broken Link
- https://www.debian.org/security/2020/dsa-4638Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2020.htmlPatch, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00010.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00015.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00025.htmlMailing List, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0514Third Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdfPatch, Third Party Advisory
- https://github.com/sqlite/sqlite/commit/75e95e1fcd52d3ec8282edb75ac8cd0814095d54Patch, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20200114-0001/Third Party Advisory
- https://usn.ubuntu.com/4298-1/Broken Link
- https://www.debian.org/security/2020/dsa-4638Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2020.htmlPatch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.