CVE-2025-70873

Name
CVE-2025-70873
Description
An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cve@mitre.org https://gist.github.com/cnwangjihe/f496393f30f5ecec5b18c8f5ab072054
cve@mitre.org https://sqlite.org/forum/forumpost/761eac3c82
cve@mitre.org https://sqlite.org/src/info/3d459f1fb1bd1b5e

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:sqlite:sqlite:*:*:*:*:*:*:*:* sqlite >= None < 3.51.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
sqlite edge-main 3.51.0-r0 Celeste <cielesti@protonmail.com> possibly vulnerable
sqlite edge-main 3.50.4-r1 Celeste <cielesti@protonmail.com> possibly vulnerable
sqlite edge-main 3.50.4-r0 Celeste <cielesti@protonmail.com> possibly vulnerable
sqlite edge-main 3.50.3-r0 Celeste <cielesti@protonmail.com> possibly vulnerable
sqlite edge-main 3.50.2-r0 Celeste <cielesti@protonmail.com> possibly vulnerable
sqlite edge-main 3.50.1-r0 Celeste <cielesti@protonmail.com> possibly vulnerable
sqlite edge-main 3.50.0-r0 Celeste <cielesti@protonmail.com> possibly vulnerable
sqlite edge-main 3.49.2-r0 Celeste <cielesti@protonmail.com> possibly vulnerable
sqlite edge-main 3.49.1-r1 Celeste <cielesti@protonmail.com> possibly vulnerable
sqlite edge-main 3.49.1-r0 Celeste <cielesti@protonmail.com> possibly vulnerable
sqlite edge-main 3.49.0-r1 Celeste <cielesti@protonmail.com> possibly vulnerable
sqlite edge-main 3.49.0-r0 Celeste <cielesti@protonmail.com> possibly vulnerable
sqlite edge-main 3.48.0-r1 Celeste <cielesti@protonmail.com> possibly vulnerable
sqlite edge-main 3.48.0-r0 Celeste <cielesti@protonmail.com> possibly vulnerable
sqlite edge-main 3.47.2-r0 Celeste <cielesti@protonmail.com> possibly vulnerable
sqlite edge-main 3.47.1-r0 Celeste <cielesti@protonmail.com> possibly vulnerable
sqlite edge-main 3.36.0-r0 Carlo Landmeter <clandmeter@alpinelinux.org> possibly vulnerable
sqlite edge-main 3.34.1-r0 None possibly vulnerable
sqlite edge-main 3.32.1-r0 None possibly vulnerable
sqlite edge-main 3.30.1-r3 None possibly vulnerable
sqlite edge-main 3.30.1-r1 None possibly vulnerable
sqlite edge-main 3.28.0-r0 None possibly vulnerable
sqlite 3.22-main 3.49.2-r1 Celeste <cielesti@protonmail.com> possibly vulnerable
sqlite 3.22-main 3.49.2-r0 Celeste <cielesti@protonmail.com> possibly vulnerable
sqlite 3.22-main 3.34.1-r0 None possibly vulnerable
sqlite 3.22-main 3.32.1-r0 None possibly vulnerable
sqlite 3.22-main 3.30.1-r3 None possibly vulnerable
sqlite 3.22-main 3.30.1-r1 None possibly vulnerable
sqlite 3.22-main 3.28.0-r0 None possibly vulnerable
sqlite 3.21-main 3.48.0-r4 Celeste <cielesti@protonmail.com> possibly vulnerable
sqlite 3.21-main 3.48.0-r3 Celeste <cielesti@protonmail.com> possibly vulnerable
sqlite 3.21-main 3.48.0-r2 Celeste <cielesti@protonmail.com> possibly vulnerable
sqlite 3.21-main 3.48.0-r1 Celeste <cielesti@protonmail.com> possibly vulnerable
sqlite 3.21-main 3.48.0-r0 Celeste <cielesti@protonmail.com> possibly vulnerable
sqlite 3.21-main 3.47.1-r0 Celeste <cielesti@protonmail.com> possibly vulnerable
sqlite 3.21-main 3.34.1-r0 None possibly vulnerable
sqlite 3.21-main 3.32.1-r0 None possibly vulnerable
sqlite 3.21-main 3.30.1-r3 None possibly vulnerable
sqlite 3.21-main 3.30.1-r1 None possibly vulnerable
sqlite 3.21-main 3.28.0-r0 None possibly vulnerable
sqlite 3.20-main 3.45.3-r3 Celeste <cielesti@protonmail.com> possibly vulnerable
sqlite 3.20-main 3.45.3-r2 Celeste <cielesti@protonmail.com> possibly vulnerable
sqlite 3.20-main 3.45.3-r1 Celeste <cielesti@protonmail.com> possibly vulnerable
sqlite 3.20-main 3.34.1-r0 None possibly vulnerable
sqlite 3.20-main 3.32.1-r0 None possibly vulnerable
sqlite 3.20-main 3.30.1-r3 None possibly vulnerable
sqlite 3.20-main 3.30.1-r1 None possibly vulnerable
sqlite 3.20-main 3.28.0-r0 None possibly vulnerable
sqlite 3.19-main 3.44.2-r2 Carlo Landmeter <clandmeter@alpinelinux.org> possibly vulnerable
sqlite 3.19-main 3.44.2-r1 Carlo Landmeter <clandmeter@alpinelinux.org> possibly vulnerable
sqlite 3.19-main 3.44.2-r0 Carlo Landmeter <clandmeter@alpinelinux.org> possibly vulnerable
sqlite 3.19-main 3.34.1-r0 None possibly vulnerable
sqlite 3.19-main 3.32.1-r0 None possibly vulnerable
sqlite 3.19-main 3.30.1-r3 None possibly vulnerable
sqlite 3.19-main 3.30.1-r1 None possibly vulnerable
sqlite 3.19-main 3.28.0-r0 None possibly vulnerable