CVE-2018-20346

Name
CVE-2018-20346
Description
SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries that occur after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases), aka Magellan.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Release Notes https://www.sqlite.org/releaselog/3_25_3.html
Mailing List https://www.mail-archive.com/sqlite-users@mailinglists.sqlite.org/msg113218.html
Permissions Required https://crbug.com/900910
Third Party Advisory https://chromium.googlesource.com/chromium/src/+/c368e30ae55600a1c3c9cb1710a54f9c55de786e
Third Party Advisory https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html
Issue Tracking https://bugzilla.redhat.com/show_bug.cgi?id=1659677
Issue Tracking https://bugzilla.redhat.com/show_bug.cgi?id=1659379
Third Party Advisory https://blade.tencent.com/magellan/index_en.html
Third Party Advisory https://access.redhat.com/articles/3758321
Exploit https://worthdoingbadly.com/sqlitebug/
Patch https://sqlite.org/src/info/d44318f59044162e
Patch https://sqlite.org/src/info/940f2adc8541a838
Third Party Advisory https://news.ycombinator.com/item?id=18685296
Exploit https://github.com/zhuowei/worthdoingbadly.com/blob/master/_posts/2018-12-14-sqlitebug.html
Mailing List https://lists.debian.org/debian-lts-announce/2018/12/msg00012.html
Third Party Advisory https://www.synology.com/security/advisory/Synology_SA_18_61
Third Party Advisory http://www.securityfocus.com/bid/106323
Third Party Advisory https://www.freebsd.org/security/advisories/FreeBSD-EN-19:03.sqlite.asc
Third Party Advisory http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00040.html
Mailing List http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00070.html
Third Party Advisory https://security.gentoo.org/glsa/201904-21
UBUNTU https://usn.ubuntu.com/4019-1/
UBUNTU https://usn.ubuntu.com/4019-2/
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PU4NZ6DDU4BEM3ACM3FM6GLEPX56ZQXK/
CONFIRM https://support.apple.com/HT209448
CONFIRM https://support.apple.com/HT209447
CONFIRM https://support.apple.com/HT209446
CONFIRM https://support.apple.com/HT209451
CONFIRM https://support.apple.com/HT209443
CONFIRM https://support.apple.com/HT209450
N/A https://www.oracle.com/security-alerts/cpuapr2020.html
MLIST https://lists.debian.org/debian-lts-announce/2020/08/msg00037.html
CONFIRM https://kc.mcafee.com/corporate/index?page=content&id=SB10365

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:sqlite:sqlite:*:*:*:*:*:*:*:* sqlite >= None < 3.25.3

Vulnerable and fixed packages

Source package Branch Version Maintainer Status