VulnerabilityModified
CVE-2022-35737
SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.
HIGH 7.5EPSS 21.5%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 21.5%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 21.45% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-129
- Affected
- sqlite/sqlite · netapp/ontap select deploy administration utility · splunk/universal forwarder
- Source
- cve@mitre.org
References
- https://blog.trailofbits.com/2022/10/25/sqlite-vulnerability-july-2022-library-api/Exploit, Third Party Advisory
- https://kb.cert.org/vuls/id/720344Broken Link, Third Party Advisory, US Government Resource
- https://security.gentoo.org/glsa/202210-40Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220915-0009/Third Party Advisory
- https://sqlite.org/releaselog/3_39_2.htmlRelease Notes, Vendor Advisory
- https://www.sqlite.org/cves.htmlVendor Advisory
- https://blog.trailofbits.com/2022/10/25/sqlite-vulnerability-july-2022-library-api/Exploit, Third Party Advisory
- https://kb.cert.org/vuls/id/720344Broken Link, Third Party Advisory, US Government Resource
- https://security.gentoo.org/glsa/202210-40Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220915-0009/Third Party Advisory
- https://sqlite.org/releaselog/3_39_2.htmlRelease Notes, Vendor Advisory
- https://www.sqlite.org/cves.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.