ZeroHour

CVE-2019-16168

CVSS 3.1
6.5 medium
EPSS
4%p90
Published
()
Modified
Description

In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validation of a sqlite_stat1 sz field, aka a "severe division by zero in the query planner."

Vendors
sqlitenetappcanonicalfedoraprojectdebiantenableoraclemcafee
Products
sqlite, active iq unified manager, e-series santricity os controller, oncommand insight, oncommand workflow automation, ontap select deploy administration utility, santricity unified manager, steelstore cloud integrated storage, ubuntu linux, fedora, debian linux, nessus agent
Weakness
CWE-369
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.