Out-of-bounds read in SQLite - CVE-2019-9936
Published: March 22, 2019
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition within the fts5HashEntrySort in sqlite3.c when running fts5 prefix queries inside a transaction. A remote user with ability to send queries can trigger heap-based buffer over-read error and read contents of memory on the system.
Affected software
Gentoo Linux
Opensuse
Fedora
Netezza Appliance
Dell PowerProtect Cyber Recovery
sqlite3 (Ubuntu package)
sqlite
Autodesk Infraworks
Dell EMC Container Storage Modules
How to mitigate CVE-2019-9936
Netezza Appliance - update to 1.0.0.1
sqlite3 (Ubuntu package) - addressed in versions 3.11.0-1ubuntu1.2, 3.22.0-1ubuntu0.1, 3.24.0-1ubuntu0.1, 3.27.2-2ubuntu0.1
Autodesk Infraworks - addressed in versions 2021.2 Hotfix 9, 2023.1 Hotfix 1
Dell EMC Container Storage Modules - update to 1.7.0
sqlite - addressed in versions 3.26.0-3.fc29, 3.26.0-5.fc30
Dell PowerProtect Cyber Recovery - update to 18.1.1.2-8
External References
Related Security Bulletins
- Multiple vulnerabilities in SQLite
- OpenSUSE Linux update for sqlite3
- Gentoo update for SQLite
- Ubuntu update for SQLite
- Multiple vulnerabilities in Dell EMC Cyber Recovery
- Multiple vulnerabilities in Autodesk InfraWorks
- Multiple vulnerabilities in Dell Container Storage Modules
- Fedora 30 update for sqlite
- Fedora 29 update for sqlite
- Multiple vulnerabilities in IBM Netezza Appliance