CVE-2019-19244

Name
CVE-2019-19244
Description
sqlite3Select in select.c in SQLite 3.30.1 allows a crash if a sub-select uses both DISTINCT and window functions, and also has certain ORDER BY usage.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Patch https://github.com/sqlite/sqlite/commit/e59c562b3f6894f84c715772c4b116d7b5c01348
Third Party Advisory https://usn.ubuntu.com/4205-1/
N/A https://www.oracle.com/security-alerts/cpuapr2020.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:sqlite:sqlite:3.30.1:*:*:*:*:*:*:* sqlite == None == 3.30.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
sqlite 3.11-main 3.30.1-r2 Carlo Landmeter <clandmeter@gmail.com> fixed