Memory leak in SQLite - CVE-2019-20218
Published: January 7, 2020 / Updated: January 22, 2020
Vulnerability identifier: #VU24065
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-20218
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due memory leak within the selectExpander() function in select.c in SQLite, caused by incorrect exception handling, related to stack unwinding. A remote attacker can trigger with ability to modify the WITH SQL query can gain access to potentially sensitive information.
Affected software
SQLite
Gentoo Linux
SUSE Manager Server
SUSE CaaS Platform
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE MicroOS
SUSE Enterprise Storage
HPE Helion Openstack
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Debuginfo
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
Red Hat OpenShift Serverless
Quay
OpenShift Data Foundation (formerly OpenShift Container Storage)
EMC Integrated Data Protection Appliance
sqlite (Red Hat package)
sqlite3
sqlite3-debuginfo
libsqlite3-0-32bit
libsqlite3-0
sqlite3-debugsource
sqlite3-devel
libsqlite3-0-32bit-debuginfo
libsqlite3-0-debuginfo
libsqlite3-0-debuginfo-32bit
Dell EMC Data Protection Search
Autodesk Infraworks
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC VxRail Appliance
Gentoo Linux
SUSE Manager Server
SUSE CaaS Platform
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE MicroOS
SUSE Enterprise Storage
HPE Helion Openstack
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Debuginfo
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
Red Hat OpenShift Serverless
Quay
OpenShift Data Foundation (formerly OpenShift Container Storage)
EMC Integrated Data Protection Appliance
sqlite (Red Hat package)
sqlite3
sqlite3-debuginfo
libsqlite3-0-32bit
libsqlite3-0
sqlite3-debugsource
sqlite3-devel
libsqlite3-0-32bit-debuginfo
libsqlite3-0-debuginfo
libsqlite3-0-debuginfo-32bit
Dell EMC Data Protection Search
Autodesk Infraworks
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC VxRail Appliance
How to mitigate CVE-2019-20218
Install updates from vendor's website.
SQLite - update to 3.31.0
Red Hat OpenShift Serverless - addressed in versions 1.10.2, 1.11.0, 1.12.0
EMC Integrated Data Protection Appliance - update to 2.7.1
Quay - update to 3.3.3
sqlite (Red Hat package) - update to 3.26.0-11.el8
Dell EMC Data Protection Search - update to 19.6.0
Autodesk Infraworks - addressed in versions 2021.2 Hotfix 9, 2023.1 Hotfix 1
sqlite3 - addressed in versions 3.7.6.3-1.4.7.15.1, 3.36.0-3.12.1, 3.36.0-9.18.1
sqlite3-debuginfo - addressed in versions 3.7.6.3-1.4.7.15.1, 3.36.0-3.12.1, 3.36.0-9.18.1
libsqlite3-0-32bit - addressed in versions 3.7.6.3-1.4.7.15.1, 3.36.0-3.12.1, 3.36.0-9.18.1
libsqlite3-0 - addressed in versions 3.7.6.3-1.4.7.15.1, 3.36.0-3.12.1, 3.36.0-9.18.1
sqlite3-debugsource - addressed in versions 3.36.0-3.12.1, 3.36.0-9.18.1
sqlite3-devel - addressed in versions 3.36.0-3.12.1, 3.36.0-9.18.1
libsqlite3-0-32bit-debuginfo - update to 3.36.0-3.12.1
libsqlite3-0-debuginfo - addressed in versions 3.36.0-3.12.1, 3.36.0-9.18.1
libsqlite3-0-debuginfo-32bit - update to 3.36.0-9.18.1
Dell EMC Unity Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity XT Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity VSA Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC VxRail Appliance - update to 7.0.203
Red Hat OpenShift Serverless - addressed in versions 1.10.2, 1.11.0, 1.12.0
EMC Integrated Data Protection Appliance - update to 2.7.1
Quay - update to 3.3.3
sqlite (Red Hat package) - update to 3.26.0-11.el8
Dell EMC Data Protection Search - update to 19.6.0
Autodesk Infraworks - addressed in versions 2021.2 Hotfix 9, 2023.1 Hotfix 1
sqlite3 - addressed in versions 3.7.6.3-1.4.7.15.1, 3.36.0-3.12.1, 3.36.0-9.18.1
sqlite3-debuginfo - addressed in versions 3.7.6.3-1.4.7.15.1, 3.36.0-3.12.1, 3.36.0-9.18.1
libsqlite3-0-32bit - addressed in versions 3.7.6.3-1.4.7.15.1, 3.36.0-3.12.1, 3.36.0-9.18.1
libsqlite3-0 - addressed in versions 3.7.6.3-1.4.7.15.1, 3.36.0-3.12.1, 3.36.0-9.18.1
sqlite3-debugsource - addressed in versions 3.36.0-3.12.1, 3.36.0-9.18.1
sqlite3-devel - addressed in versions 3.36.0-3.12.1, 3.36.0-9.18.1
libsqlite3-0-32bit-debuginfo - update to 3.36.0-3.12.1
libsqlite3-0-debuginfo - addressed in versions 3.36.0-3.12.1, 3.36.0-9.18.1
libsqlite3-0-debuginfo-32bit - update to 3.36.0-9.18.1
Dell EMC Unity Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity XT Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity VSA Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC VxRail Appliance - update to 7.0.203
External References
Related Security Bulletins
- Multiple vulnerabilities in SQLite
- Gentoo update for SQLite
- Red Hat Enterprise Linux 8 update for sqlite
- Multiple vulnerabilities in Red Hat Openshift Serverless
- Multiple vulnerabilities in Red Hat OpenShift Container Storage
- Multiple vulnerabilities in Red Hat Quay
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Multiple vulnerabilities in Dell EMC Integrated Data Protection Appliance
- Multiple vulnerabilities in Dell EMC Data Protection Search
- SUSE update for sqlite3
- SUSE update for sqlite3
- SUSE update for sqlite3
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Multiple vulnerabilities in Autodesk InfraWorks
- Multiple vulnerabilities in Dell Unity, Dell UnityVSA, and Dell Unity XT