Use-after-free in SQLite - CVE-2020-11656

 

Use-after-free in SQLite - CVE-2020-11656

Published: April 20, 2020 / Updated: October 28, 2023


Vulnerability identifier: #VU27024
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-11656
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error in the ALTER TABLE implementation. A remote attacker can execute arbitrary code on the target system, as demonstrated by an ORDER BY clause that belongs to a compound SELECT statement.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


Affected software

SQLite
Gentoo Linux
FreeBSD
Junos OS
Junos OS Evolved
ONTAP Select Deploy administration utility
VMware Horizon Client
DataEdgePlatform DataMosaix Private Cloud
Telemetry Dashboard
Oracle Communications Network Charging and Control
Liquidware
Citrix Workspace App
Webex App VDI
Tenable.sc
PowerScale OneFS
Cisco Jabber
Cisco Webex Meetings
SINEC INS
IBM QRadar Data Synchronization App

How to mitigate CVE-2020-11656

Install update from vendor's website.

SQLite - update to 3.32.0
DataEdgePlatform DataMosaix Private Cloud - update to 7.11.01
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
Tenable.sc - update to 5.19.0
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Junos OS - addressed in versions 19.3R3-S6, 19.4R2-S6, 19.4R3-S8, 20.1R3-S4, 20.2R3-S4, 20.3R3-S3
Junos OS Evolved - addressed in versions 21.2R3-EVO, 21.3R3-EVO, 21.4R2-EVO, 22.1R1-EVO
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
SINEC INS - update to 1.0.1.1
IBM QRadar Data Synchronization App - update to 3.0.1

External References

Related Security Bulletins