Division by zero in SQLite - CVE-2019-16168
Published: December 2, 2019 / Updated: June 20, 2021
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service attack.
The vulnerability exists due to a division by zero error within the whereLoopAddBtreeIndex in sqlite3.c due to improper input validation in the sqlite_stat1 sz field. A remote attacker can pass specially crafted data to the application, trigger division by zero error and crash the vulnerable application.
Affected software
Gentoo Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
HPE Helion Openstack
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
Opensuse
Fedora
Wyse ThinLinux
Telemetry Dashboard
Liquidware
Citrix Workspace App
Webex App VDI
EMC ECS
sqlite (Alpine package)
sqlite3 (Ubuntu package)
sqlite (Red Hat package)
mingw-bzip2 (Red Hat package)
mingw-binutils (Red Hat package)
mingw-sqlite (Red Hat package)
sqlite
libsqlite3-0
sqlite3-devel
sqlite3-debugsource
sqlite3-debuginfo
sqlite3
libsqlite3-0-debuginfo
libsqlite3-0-32bit
libsqlite3-0-debuginfo-32bit
mingw-filesystem (Red Hat package)
Red Hat OpenShift Serverless
Quay
OpenShift Data Foundation (formerly OpenShift Container Storage)
EMC Integrated Data Protection Appliance
Tenable.sc
Oracle Communications Design Studio
Tenable Nessus
Dell EMC Data Protection Search
Nessus Agent
Oracle Outside In Technology
Oracle Java SE
MySQL Workbench
Cisco Jabber
Cisco Webex Meetings
VMware Horizon Client
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
How to mitigate CVE-2019-16168
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
Red Hat OpenShift Serverless - addressed in versions 1.10.2, 1.11.0, 1.12.0
EMC Integrated Data Protection Appliance - update to 2.7.1
Quay - update to 3.3.3
sqlite3 (Ubuntu package) - addressed in versions 3.11.0-1ubuntu1.3, 3.22.0-1ubuntu0.2, 3.27.2-2ubuntu0.2, 3.29.0-2ubuntu0.1
sqlite (Alpine package) - update to 3.25.3-r2
sqlite (Red Hat package) - update to 3.26.0-11.el8
Tenable.sc - update to 5.19.0
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
Tenable Nessus - update to 8.15.0
Nessus Agent - update to 8.2.4
MySQL Workbench - update to 8.0.19
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Dell EMC Data Protection Search - update to 19.6.0
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
mingw-bzip2 (Red Hat package) - update to 1.0.6-14.el8
Wyse ThinLinux - update to 2.2.1.01
mingw-binutils (Red Hat package) - update to 2.30-3.el8
EMC ECS - update to 3.5.0.1
mingw-sqlite (Red Hat package) - update to 3.26.0.0-1.el8
sqlite - addressed in versions 3.26.0-5.fc29, 3.26.0-7.fc30
libsqlite3-0 - update to 3.36.0-9.18.1
sqlite3-devel - update to 3.36.0-9.18.1
sqlite3-debugsource - update to 3.36.0-9.18.1
sqlite3-debuginfo - update to 3.36.0-9.18.1
sqlite3 - update to 3.36.0-9.18.1
libsqlite3-0-debuginfo - update to 3.36.0-9.18.1
libsqlite3-0-32bit - update to 3.36.0-9.18.1
libsqlite3-0-debuginfo-32bit - update to 3.36.0-9.18.1
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.3.0.5.014
Dell EMC Unity Operating Environment (OE) - update to 5.0.3.0.5.014
mingw-filesystem (Red Hat package) - update to 104-2.el8
External References
Related Security Bulletins
- Ubuntu update for SQLite
- OpenSUSE Linux update for sqlite3
- OpenSUSE Linux update for sqlite3
- Multiple vulnerabilities in Oracle Communications Design Studio
- Gentoo update for SQLite
- Multiple vulnerabilities in Oracle Outside In Technology
- Division by zero in MySQL Workbench
- Multiple vulnerabilities in Java SE
- Division by zero in sqlite (Alpine package)
- Red Hat Enterprise Linux 8 update for sqlite
- Multiple vulnerabilities in Red Hat Openshift Serverless
- Multiple vulnerabilities in Red Hat OpenShift Container Storage
- Multiple vulnerabilities in Red Hat Quay
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Multiple vulnerabilities in Tenable Nessus Agent
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Multiple vulnerabilities in Red Hat CodeReady Linux Builder
- Multiple vulnerabilities in Tenable Nessus
- Multiple vulnerabilities in Tenable.sc
- Multiple vulnerabilities in Dell EMC Integrated Data Protection Appliance
- Multiple vulnerabilities in Dell EMC Data Protection Search
- SUSE update for sqlite3
- Multiple vulnerabilities in Dell EMC ECS
- Multiple vulnerabilities in Dell Wyse ThinLinux
- Multiple vulnerabilities in Dell ThinOS
- Fedora 30 update for sqlite
- Fedora 29 update for sqlite
- Dell EMC Unity update for third-party components