ZeroHour

CVE-2019-19880

CVSS 3.1
7.5 high
EPSS
7%p94
Published
()
Modified
Description

exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values in ORDER BY clauses of window definitions are mishandled.

Vendors
sqlitenetappdebiansuseredhatopensuseoraclesiemens
Products
sqlite, cloud backup, debian linux, package hub, enterprise linux desktop, enterprise linux server, enterprise linux workstation, backports sle, leap, mysql workbench, sinec infrastructure network services
Weakness
CWE-476
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.