VulnerabilityModified
CVE-2021-31239
An issue found in SQLite SQLite3 v.3.35.4 that allows a remote attacker to cause a denial of service via the appendvfs.c function.
HIGH 7.5EPSS 2.16%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.16%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue found in SQLite SQLite3 v.3.35.4 that allows a remote attacker to cause a denial of service via the appendvfs.c function.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 2.16% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-125
- Affected
- sqlite/sqlite
- Source
- cve@mitre.org
References
- https://github.com/Tsiming/Vulnerabilities/blob/main/SQLite/CVE-2021-31239Exploit, Patch
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/73XUIHJ6UT75VFPDPLJOXJON7MVIKVZI/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FXFL4TDAH72PRCPD5UPZMJMKIMVOPLTI/
- https://security.gentoo.org/glsa/202311-03
- https://security.netapp.com/advisory/ntap-20230609-0010/
- https://www.sqlite.org/cves.htmlVendor Advisory
- https://www.sqlite.org/forum/forumpost/d9fce1a89bMitigation
- https://github.com/Tsiming/Vulnerabilities/blob/main/SQLite/CVE-2021-31239Exploit, Patch
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/73XUIHJ6UT75VFPDPLJOXJON7MVIKVZI/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FXFL4TDAH72PRCPD5UPZMJMKIMVOPLTI/
- https://security.gentoo.org/glsa/202311-03
- https://security.netapp.com/advisory/ntap-20230609-0010/
- https://www.sqlite.org/cves.htmlVendor Advisory
- https://www.sqlite.org/forum/forumpost/d9fce1a89bMitigation
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.