ZeroHour

CVE-2019-19923

CVSS 3.1
7.5 high
EPSS
7%p94
Published
()
Modified
Description

flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which the right-hand side is a view. This can cause a NULL pointer dereference (or incorrect results).

Vendors
sqlitesiemensoracledebianredhatsuseopensusenetapp
Products
sqlite, sinec infrastructure network services, mysql workbench, debian linux, enterprise linux desktop, enterprise linux server, enterprise linux workstation, package hub, backports sle, leap, cloud backup
Weakness
CWE-476
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.