CVE-2022-35737

Name
CVE-2022-35737
Description
SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://kb.cert.org/vuls/id/720344
MISC https://www.sqlite.org/cves.html
Release Notes https://sqlite.org/releaselog/3_39_2.html
Third Party Advisory https://security.netapp.com/advisory/ntap-20220915-0009/
Exploit https://blog.trailofbits.com/2022/10/25/sqlite-vulnerability-july-2022-library-api/
Third Party Advisory https://security.gentoo.org/glsa/202210-40

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:sqlite:sqlite:*:*:*:*:*:*:*:* sqlite >= 1.0.12 < 3.39.2

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
sqlite edge-main 3.36.0-r0 Carlo Landmeter <clandmeter@alpinelinux.org> fixed
sqlite edge-main 3.34.1-r0 None fixed
sqlite edge-main 3.32.1-r0 None fixed
sqlite edge-main 3.30.1-r3 None fixed
sqlite edge-main 3.30.1-r1 None fixed
sqlite edge-main 3.28.0-r0 None fixed
sqlite 3.22-main 3.34.1-r0 None fixed
sqlite 3.22-main 3.32.1-r0 None fixed
sqlite 3.22-main 3.30.1-r3 None fixed
sqlite 3.22-main 3.30.1-r1 None fixed
sqlite 3.22-main 3.28.0-r0 None fixed
sqlite 3.21-main 3.34.1-r0 None fixed
sqlite 3.21-main 3.32.1-r0 None fixed
sqlite 3.21-main 3.30.1-r3 None fixed
sqlite 3.21-main 3.30.1-r1 None fixed
sqlite 3.21-main 3.28.0-r0 None fixed
sqlite 3.20-main 3.34.1-r0 None fixed
sqlite 3.20-main 3.32.1-r0 None fixed
sqlite 3.20-main 3.30.1-r3 None fixed
sqlite 3.20-main 3.30.1-r1 None fixed
sqlite 3.20-main 3.28.0-r0 None fixed
sqlite 3.19-main 3.34.1-r0 None fixed
sqlite 3.19-main 3.32.1-r0 None fixed
sqlite 3.19-main 3.30.1-r3 None fixed
sqlite 3.19-main 3.30.1-r1 None fixed
sqlite 3.19-main 3.28.0-r0 None fixed
qt5-qtwebengine edge-community 5.15.11-r3 Bart Ribbers <bribbers@disroot.org> fixed
qt5-qtwebengine 3.22-community 5.15.11-r3 None fixed
qt5-qtwebengine 3.21-community 5.15.11-r3 None fixed
qt5-qtwebengine 3.20-community 5.15.11-r3 None fixed
qt5-qtwebengine 3.19-community 5.15.11-r3 None fixed
qt5-qtwebengine 3.18-community 5.15.11-r3 None fixed
qt5-qtwebengine 3.17-community 5.15.11-r3 None fixed