NULL pointer dereference in SQLite - CVE-2019-9937
Published: March 22, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dreference error when processing interleaving reads and writes in a single transaction with an fts5 virtual table in fts5ChunkIterate in sqlite3.c. This is related to ext/fts5/fts5_hash.c and ext/fts5/fts5_index.c. A remote attacker can perform a denial of service (DoS) attack.
Affected software
Gentoo Linux
Opensuse
Fedora
Netezza Appliance
Dell PowerProtect Cyber Recovery
sqlite3 (Ubuntu package)
sqlite
Autodesk Infraworks
Dell EMC Container Storage Modules
How to mitigate CVE-2019-9937
Netezza Appliance - update to 1.0.0.1
sqlite3 (Ubuntu package) - addressed in versions 3.11.0-1ubuntu1.2, 3.22.0-1ubuntu0.1, 3.24.0-1ubuntu0.1, 3.27.2-2ubuntu0.1
Autodesk Infraworks - addressed in versions 2021.2 Hotfix 9, 2023.1 Hotfix 1
Dell EMC Container Storage Modules - update to 1.7.0
sqlite - addressed in versions 3.26.0-3.fc29, 3.26.0-5.fc30
Dell PowerProtect Cyber Recovery - update to 18.1.1.2-8
External References
Related Security Bulletins
- Multiple vulnerabilities in SQLite
- OpenSUSE Linux update for sqlite3
- Gentoo update for SQLite
- Ubuntu update for SQLite
- Multiple vulnerabilities in Dell EMC Cyber Recovery
- Multiple vulnerabilities in Autodesk InfraWorks
- Multiple vulnerabilities in Dell Container Storage Modules
- Fedora 30 update for sqlite
- Fedora 29 update for sqlite
- Multiple vulnerabilities in IBM Netezza Appliance