CVE-2018-20505

SQLite 3.25.2, when queries are run on a table with a malformed PRIMARY KEY, allows remote attackers to cause a denial of service (application crash) by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases).
References
Link Resource
https://support.apple.com/kb/HT209451 Vendor Advisory
https://support.apple.com/kb/HT209450 Vendor Advisory
https://support.apple.com/kb/HT209448 Vendor Advisory
https://support.apple.com/kb/HT209447 Vendor Advisory
https://support.apple.com/kb/HT209446 Vendor Advisory
https://support.apple.com/kb/HT209443 Vendor Advisory
https://sqlite.org/src/info/1a84668dcfdebaf12415d Exploit Vendor Advisory
https://seclists.org/bugtraq/2019/Jan/39 Mailing List Third Party Advisory
https://seclists.org/bugtraq/2019/Jan/33 Mailing List Third Party Advisory
https://seclists.org/bugtraq/2019/Jan/32 Mailing List Third Party Advisory
https://seclists.org/bugtraq/2019/Jan/31 Mailing List Third Party Advisory
https://seclists.org/bugtraq/2019/Jan/29 Mailing List Third Party Advisory
https://seclists.org/bugtraq/2019/Jan/28 Mailing List Third Party Advisory
http://www.securityfocus.com/bid/106698 Third Party Advisory VDB Entry
http://seclists.org/fulldisclosure/2019/Jan/69 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2019/Jan/68 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2019/Jan/67 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2019/Jan/66 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2019/Jan/64 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2019/Jan/62 Mailing List Third Party Advisory
https://security.netapp.com/advisory/ntap-20190502-0004/ Third Party Advisory
https://usn.ubuntu.com/4019-1/
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:sqlite:sqlite:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
OR cpe:2.3:a:apple:icloud:*:*:*:*:*:*:*:*
cpe:2.3:a:apple:itunes:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

Information

Published : 2019-04-03 11:29

Updated : 2019-06-19 12:15


NVD link : CVE-2018-20505

Mitre link : CVE-2018-20505


JSON object : View

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Advertisement

dedicated server usa

Products Affected

apple

  • itunes
  • icloud
  • mac_os_x
  • watchos
  • iphone_os

microsoft

  • windows

sqlite

  • sqlite