SQL injection in Apple iOS - CVE-2018-20346
Published: January 23, 2019 / Updated: January 29, 2019
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary SQL queries in database.
The vulnerability exists due to insufficient sanitization of user-supplied data in the SQLite component. A remote attacker can send a specially specially crafted request to the affected application and execute arbitrary SQL commands within the application database.
Successful exploitation of this vulnerability may allow a remote attacker to read, delete, modify data in database and gain complete control over the affected application.
Affected software
Gentoo Linux
watchOS
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
macOS
tvOS
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
Opensuse
Fedora
Telemetry Dashboard
Liquidware
Citrix Workspace App
Webex App VDI
Dell PowerProtect Cyber Recovery
EMC Integrated Data Protection Appliance
sqlite3 (Ubuntu package)
sqlite (Alpine package)
mingw-sqlite
libsqlite3-0-debuginfo-32bit
sqlite3-devel
sqlite3-debugsource
sqlite3-debuginfo
sqlite3
libsqlite3-0-debuginfo
libsqlite3-0-32bit
libsqlite3-0
iCloud for Windows
iTunes
Cisco Jabber
Dell EMC Data Protection Search
Cisco Webex Meetings
VMware Horizon Client
Flex System Chassis Management Module (CMM)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
How to mitigate CVE-2018-20346
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
EMC Integrated Data Protection Appliance - update to 2.7.1
sqlite3 (Ubuntu package) - addressed in versions 3.11.0-1ubuntu1.2, 3.22.0-1ubuntu0.1, 3.24.0-1ubuntu0.1, 3.27.2-2ubuntu0.1
sqlite (Alpine package) - update to 3.25.3-r0
watchOS - update to 5.1.3
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
iCloud for Windows - update to 7.10
macOS - update to 10.14.3 18D42
tvOS - update to 12.1.2
iTunes - update to 12.9.3
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Dell EMC Data Protection Search - update to 19.6.0
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
Flex System Chassis Management Module (CMM) - update to 2pet18c-2.5.16c
mingw-sqlite - update to 3.26.0.0-1.fc29
libsqlite3-0-debuginfo-32bit - update to 3.36.0-9.18.1
sqlite3-devel - update to 3.36.0-9.18.1
sqlite3-debugsource - update to 3.36.0-9.18.1
sqlite3-debuginfo - update to 3.36.0-9.18.1
sqlite3 - update to 3.36.0-9.18.1
libsqlite3-0-debuginfo - update to 3.36.0-9.18.1
libsqlite3-0-32bit - update to 3.36.0-9.18.1
libsqlite3-0 - update to 3.36.0-9.18.1
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.0.0.5.116
Dell EMC Unity Operating Environment (OE) - update to 5.0.0.0.5.116
Dell PowerProtect Cyber Recovery - update to 18.1.1.2-8
External References
Related Security Bulletins
- Multiple vulnerabilities in Apple iOS
- Multiple vulnerabilities in Apple macOS
- Multiple vulnerabilities in Apple iCloud
- Multiple vulnerabilities in Apple watchOS
- Multiple vulnerabilities in Apple tvOS
- Multiple vulnerabilities in Apple iTunes
- OpenSUSE Linux update for sqlite3
- OpenSUSE Linux update for sqlite3
- Gentoo update for SQLite
- Ubuntu update for SQLite
- SQL injection in sqlite (Alpine package)
- Multiple vulnerabilities in Dell EMC Integrated Data Protection Appliance
- Multiple vulnerabilities in Dell EMC Data Protection Search
- SUSE update for sqlite3
- Multiple vulnerabilities in Dell EMC Cyber Recovery
- Multiple vulnerabilities in Dell EMC Unity Family
- Multiple vulnerabilities in Dell ThinOS
- IBM Flex System Chassis Management Module (CMM) update for SQLite
- Fedora 29 update for mingw-sqlite