NULL pointer dereference in SQLite - CVE-2020-35525

 

NULL pointer dereference in SQLite - CVE-2020-35525

Published: September 15, 2022


Vulnerability identifier: #VU67411
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-35525
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error in the INTERSEC query processing. A remote attacker can pass specially crafted data to the application and perform a denial of service (DoS) attack.


Affected software

SQLite
Oracle Linux
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Ubuntu
Service Binding Operator
Migration Toolkit for Runtimes
IBM MQ Operator
Ansible Automation Platform
Red Hat Advanced Cluster Management for Kubernetes
OpenShift Logging
Netcool Operations Insight
IBM Cloud Transformation Advisor
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Red Hat OpenShift Serverless
OpenShift Virtualization
OpenShift API for Data Protection (OADP)
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
sqlite3 (Ubuntu package)
libsqlite3-0 (Ubuntu package)
sqlite-doc
sqlite-libs
sqlite-devel
sqlite
lemon
sqlite (Red Hat package)
IBM supplied MQ Advanced container images
ObjectScale
IBM Cloud Pak for Watson AIOps
Robotic Process Automation for Cloud Pak
Cloud Pak for Security (CP4S)
RecoverPoint for VMs

How to mitigate CVE-2020-35525

Install updates from vendor's website.

SQLite - update to 3.32.0
Service Binding Operator - update to 1.3.1
Migration Toolkit for Runtimes - update to 1.0.1
Red Hat OpenShift Serverless - update to 1.26.0
OpenShift API for Data Protection (OADP) - update to 1.1.1
Migration Toolkit for Containers - update to 1.7.6
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.4.8, 2.6.2
Red Hat OpenShift Container Platform - addressed in versions 4.11.12, 4.11.45
OpenShift Logging - addressed in versions 5.3.13, 5.3.14, 5.4.8, 5.5.4, 5.5.5
IBM supplied MQ Advanced container images - update to 9.3.0.1-r3
sqlite3 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 3.11.01ubuntu1.5+esm1, 3.22.0-1ubuntu0.6, 3.31.1-4ubuntu0.4
libsqlite3-0 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
ObjectScale - update to 1.4.0
Netcool Operations Insight - update to 1.6.8
Cloud Pak for Security (CP4S) - update to 1.10.12.0
IBM Cloud Transformation Advisor - update to 3.4.0
IBM Cloud Pak for Watson AIOps - update to 3.6.1
sqlite-doc - update to 3.26.0-16
sqlite-libs - update to 3.26.0-16
sqlite-devel - update to 3.26.0-16
sqlite - update to 3.26.0-16
lemon - update to 3.26.0-16
sqlite (Red Hat package) - update to 3.26.0-16.el8_6
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.6.4
OpenShift Virtualization - addressed in versions 4.11.1, 4.12.0
RecoverPoint for VMs - update to 6.0.SP1.P1
Robotic Process Automation for Cloud Pak - update to 21.0.7

External References

Related Security Bulletins