Memory leak in SQLite - CVE-2019-20218

 

Memory leak in SQLite - CVE-2019-20218

Published: January 7, 2020 / Updated: January 22, 2020


Vulnerability identifier: #VU24065
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-20218
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due memory leak within the selectExpander() function in select.c in SQLite, caused by incorrect exception handling, related to stack unwinding. A remote attacker can trigger with ability to modify the WITH SQL query can gain access to potentially sensitive information.


Affected software

SQLite
Gentoo Linux
SUSE Manager Server
SUSE CaaS Platform
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE MicroOS
SUSE Enterprise Storage
HPE Helion Openstack
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Debuginfo
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
Red Hat OpenShift Serverless
Quay
OpenShift Data Foundation (formerly OpenShift Container Storage)
EMC Integrated Data Protection Appliance
sqlite (Red Hat package)
sqlite3
sqlite3-debuginfo
libsqlite3-0-32bit
libsqlite3-0
sqlite3-debugsource
sqlite3-devel
libsqlite3-0-32bit-debuginfo
libsqlite3-0-debuginfo
libsqlite3-0-debuginfo-32bit
Dell EMC Data Protection Search
Autodesk Infraworks
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC VxRail Appliance

How to mitigate CVE-2019-20218

Install updates from vendor's website.

SQLite - update to 3.31.0
Red Hat OpenShift Serverless - addressed in versions 1.10.2, 1.11.0, 1.12.0
EMC Integrated Data Protection Appliance - update to 2.7.1
Quay - update to 3.3.3
sqlite (Red Hat package) - update to 3.26.0-11.el8
Dell EMC Data Protection Search - update to 19.6.0
Autodesk Infraworks - addressed in versions 2021.2 Hotfix 9, 2023.1 Hotfix 1
sqlite3 - addressed in versions 3.7.6.3-1.4.7.15.1, 3.36.0-3.12.1, 3.36.0-9.18.1
sqlite3-debuginfo - addressed in versions 3.7.6.3-1.4.7.15.1, 3.36.0-3.12.1, 3.36.0-9.18.1
libsqlite3-0-32bit - addressed in versions 3.7.6.3-1.4.7.15.1, 3.36.0-3.12.1, 3.36.0-9.18.1
libsqlite3-0 - addressed in versions 3.7.6.3-1.4.7.15.1, 3.36.0-3.12.1, 3.36.0-9.18.1
sqlite3-debugsource - addressed in versions 3.36.0-3.12.1, 3.36.0-9.18.1
sqlite3-devel - addressed in versions 3.36.0-3.12.1, 3.36.0-9.18.1
libsqlite3-0-32bit-debuginfo - update to 3.36.0-3.12.1
libsqlite3-0-debuginfo - addressed in versions 3.36.0-3.12.1, 3.36.0-9.18.1
libsqlite3-0-debuginfo-32bit - update to 3.36.0-9.18.1
Dell EMC Unity Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity XT Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity VSA Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC VxRail Appliance - update to 7.0.203

External References

Related Security Bulletins