NULL pointer dereference in SQLite - CVE-2018-8740
Published: March 20, 2018 / Updated: March 20, 2018
Vulnerability identifier: #VU11173
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-8740
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote authenticated attacker to cause DoS condition on the target system.
The weakness exists in the build.c and prepare.c source codes files due to NULL pointer dereference. A remote attacker can cause the service to crash.
The weakness exists in the build.c and prepare.c source codes files due to NULL pointer dereference. A remote attacker can cause the service to crash.
Affected software
SQLite
Telemetry Dashboard
Liquidware
Citrix Workspace App
Webex App VDI
Dell PowerProtect Cyber Recovery
sqlite (Alpine package)
sqlite3 (Ubuntu package)
sqlite
mingw-sqlite
sqlite3
libsqlite3-0
libsqlite3-0-32bit
libsqlite3-0-debuginfo
sqlite3-devel
sqlite3-debugsource
sqlite3-debuginfo
libsqlite3-0-debuginfo-32bit
EMC Integrated Data Protection Appliance
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
HPE Helion Openstack
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
Fedora
Opensuse
Cisco Jabber
Dell EMC Data Protection Search
Cisco Webex Meetings
VMware Horizon Client
Telemetry Dashboard
Liquidware
Citrix Workspace App
Webex App VDI
Dell PowerProtect Cyber Recovery
sqlite (Alpine package)
sqlite3 (Ubuntu package)
sqlite
mingw-sqlite
sqlite3
libsqlite3-0
libsqlite3-0-32bit
libsqlite3-0-debuginfo
sqlite3-devel
sqlite3-debugsource
sqlite3-debuginfo
libsqlite3-0-debuginfo-32bit
EMC Integrated Data Protection Appliance
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
HPE Helion Openstack
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
Fedora
Opensuse
Cisco Jabber
Dell EMC Data Protection Search
Cisco Webex Meetings
VMware Horizon Client
How to mitigate CVE-2018-8740
Install update from vendor's website.
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
EMC Integrated Data Protection Appliance - update to 2.7.1
sqlite (Alpine package) - addressed in versions 3.20.1-r2, 3.25.3-r0
sqlite3 (Ubuntu package) - addressed in versions 3.11.0-1ubuntu1.3, 3.22.0-1ubuntu0.2, 3.27.2-2ubuntu0.2, 3.29.0-2ubuntu0.1
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Dell EMC Data Protection Search - update to 19.6.0
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
sqlite - addressed in versions 3.20.1-2.fc26, 3.20.1-2.fc27, 3.22.0-4.fc28
mingw-sqlite - update to 3.26.0.0-1.fc29
sqlite3 - update to 3.36.0-9.18.1
libsqlite3-0 - update to 3.36.0-9.18.1
libsqlite3-0-32bit - update to 3.36.0-9.18.1
libsqlite3-0-debuginfo - update to 3.36.0-9.18.1
sqlite3-devel - update to 3.36.0-9.18.1
sqlite3-debugsource - update to 3.36.0-9.18.1
sqlite3-debuginfo - update to 3.36.0-9.18.1
libsqlite3-0-debuginfo-32bit - update to 3.36.0-9.18.1
Dell PowerProtect Cyber Recovery - update to 18.1.1.2-8
EMC Integrated Data Protection Appliance - update to 2.7.1
sqlite (Alpine package) - addressed in versions 3.20.1-r2, 3.25.3-r0
sqlite3 (Ubuntu package) - addressed in versions 3.11.0-1ubuntu1.3, 3.22.0-1ubuntu0.2, 3.27.2-2ubuntu0.2, 3.29.0-2ubuntu0.1
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Dell EMC Data Protection Search - update to 19.6.0
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
sqlite - addressed in versions 3.20.1-2.fc26, 3.20.1-2.fc27, 3.22.0-4.fc28
mingw-sqlite - update to 3.26.0.0-1.fc29
sqlite3 - update to 3.36.0-9.18.1
libsqlite3-0 - update to 3.36.0-9.18.1
libsqlite3-0-32bit - update to 3.36.0-9.18.1
libsqlite3-0-debuginfo - update to 3.36.0-9.18.1
sqlite3-devel - update to 3.36.0-9.18.1
sqlite3-debugsource - update to 3.36.0-9.18.1
sqlite3-debuginfo - update to 3.36.0-9.18.1
libsqlite3-0-debuginfo-32bit - update to 3.36.0-9.18.1
Dell PowerProtect Cyber Recovery - update to 18.1.1.2-8
External References
Related Security Bulletins
- Denial of service in SQLite
- OpenSUSE Linux update for sqlite3
- Ubuntu update for SQLite
- NULL pointer dereference in sqlite (Alpine package)
- Multiple vulnerabilities in Dell EMC Integrated Data Protection Appliance
- Multiple vulnerabilities in Dell EMC Data Protection Search
- SUSE update for sqlite3
- Multiple vulnerabilities in Dell EMC Cyber Recovery
- Multiple vulnerabilities in Dell ThinOS
- Fedora 26 update for sqlite
- Fedora 27 update for sqlite
- Fedora 28 update for sqlite
- Fedora 29 update for mingw-sqlite