Buffer overflow in SQLite - CVE-2021-36690

 

Buffer overflow in SQLite - CVE-2021-36690

Published: May 25, 2022 / Updated: October 28, 2023


Vulnerability identifier: #VU63627
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-36690
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service attack.

The vulnerability exists due to a segmentation fault in the sqlite3 command-line component when processing SQL queries in the idxGetTableInfo() function. A local user can pass a specially crafted SQL query and crash the application.


Affected software

SQLite
Dell Data Protection Central
Dell EMC PowerProtect Data Protection
OpenManage Network Integration (OMNI)
EMC ECS
Enterprise SONiC
Platform Automation Toolkit
SmartFabric Storage Software
PowerScale OneFS
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
openSUSE Leap Micro
SUSE Enterprise Storage
SUSE Linux Enterprise Storage
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Desktop
openSUSE Leap
Ubuntu
Junos OS
Junos OS Evolved
watchOS
macOS
iPadOS
Apple iOS
tvOS
Isolation Segment
VMware Tanzu Application Service for VMs
Use Case Manager App
sqlite3 (Ubuntu package)
libsqlite3-0-debuginfo-32bit
libsqlite3-0
libsqlite3-0-32bit
sqlite3-tcl
sqlite3-debugsource
libsqlite3-0-debuginfo
sqlite3
sqlite3-debuginfo
sqlite3-devel
sqlite3-doc
libsqlite3-0-32bit-debuginfo
Dell EMC Storage Monitoring and Reporting (SMR)
EMC ViPR SRM
Dell EMC VxRail Appliance

How to mitigate CVE-2021-36690

Install updates from vendor's website.

SQLite - update to 3.37.0
SmartFabric Storage Software - update to 1.4.3
Junos OS - addressed in versions 19.3R3-S6, 19.4R2-S6, 19.4R3-S8, 20.1R3-S4, 20.2R3-S4, 20.3R3-S3
Junos OS Evolved - addressed in versions 21.2R3-EVO, 21.3R3-EVO, 21.4R2-EVO, 22.1R1-EVO
Isolation Segment - addressed in versions 2.7.45, 2.10.25, 2.11.14, 2.12.8
VMware Tanzu Application Service for VMs - addressed in versions 2.7.50, 2.10.32, 2.11.20, 2.12.13, 2.13.5
OpenManage Network Integration (OMNI) - update to 3.7
EMC ECS - update to 3.8.0.2
sqlite3 (Ubuntu package) - addressed in versions 3.22.0-1ubuntu0.5, 3.31.1-4ubuntu0.3, 3.35.5-1ubuntu0.1
libsqlite3-0-debuginfo-32bit - update to 3.39.3-9.23.1
libsqlite3-0 - addressed in versions 3.39.3-9.23.1, 3.39.3-150000.3.17.1
libsqlite3-0-32bit - addressed in versions 3.39.3-9.23.1, 3.39.3-150000.3.17.1
sqlite3-tcl - addressed in versions 3.39.3-9.23.1, 3.39.3-150000.3.17.1
sqlite3-debugsource - addressed in versions 3.39.3-9.23.1, 3.39.3-150000.3.17.1
libsqlite3-0-debuginfo - addressed in versions 3.39.3-9.23.1, 3.39.3-150000.3.17.1
sqlite3 - addressed in versions 3.39.3-9.23.1, 3.39.3-150000.3.17.1
sqlite3-debuginfo - addressed in versions 3.39.3-9.23.1, 3.39.3-150000.3.17.1
sqlite3-devel - addressed in versions 3.39.3-9.23.1, 3.39.3-150000.3.17.1
sqlite3-doc - update to 3.39.3-150000.3.17.1
libsqlite3-0-32bit-debuginfo - update to 3.39.3-150000.3.17.1
Use Case Manager App - update to 4.0.0
Enterprise SONiC - update to 4.4.1
Platform Automation Toolkit - addressed in versions 4.4.29, 5.0.22
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.8.0.1
EMC ViPR SRM - update to 4.8.0.1
Dell EMC VxRail Appliance - update to 7.0.411
watchOS - update to 9.0 20R361
PowerScale OneFS - update to 9.4.0.14
macOS - update to 13.0 22A380
iPadOS - update to 16.0 20A362
Apple iOS - update to 16.0 20A362
tvOS - update to 16.0 20J373

External References

Related Security Bulletins