ZeroHour

CVE-2020-15358

PoC
CVSS 3.1
5.5 medium
EPSS
1%p62
Published
()
Modified
Description

In SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation.

Vendors
sqlitecanonicalappleoraclesiemens
Products
sqlite, ubuntu linux, icloud, ipados, iphone os, macos, tvos, watchos, communications cloud native core policy, communications messaging server, communications network charging and control, enterprise manager ops center
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.