Improper Validation of Array Index in SQLite - CVE-2022-35737

 

Improper Validation of Array Index in SQLite - CVE-2022-35737

Published: September 15, 2022 / Updated: October 25, 2022


Vulnerability identifier: #VU67414
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-35737
CWE-ID: CWE-129
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error when handling an overly large input passed as argument to a C API. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.


Affected software

SQLite
Amazon Linux AMI
Gentoo Linux
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
openSUSE Leap Micro
SUSE Enterprise Storage
Oracle Linux
SUSE Linux Enterprise Storage
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Software Development Kit
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Desktop
openSUSE Leap
openEuler
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
IBM Cloud Pak for Watson AIOps
Telemetry Dashboard
RecoverPoint Classic
Oracle Communications Network Charging and Control
Liquidware
Citrix Workspace App
Webex App VDI
cflinuxfs3
PowerStore T
EMC ECS
IBM supplied MQ Advanced container images
Robotic Process Automation for Cloud Pak
Submariner
NetObserv Operator
Migration Toolkit for Runtimes
Service Telemetry Framework
Migration Toolkit for Virtualization
Red Hat Advanced Cluster Management for Kubernetes
IBM Watson Assistant for IBM Cloud Pak for Data
OpenShift Logging
Red Hat Migration Toolkit for Applications
Red Hat OpenStack
Autodesk Infraworks
Netcool Operations Insight
IBM MQ Operator
Use Case Manager App
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Self Node Remediation Operator
Red Hat OpenShift Serverless
OpenShift sandboxed containers
OpenShift Service Mesh
OpenShift Data Foundation (formerly OpenShift Container Storage)
OpenShift Container Platform for Windows Containers
Secondary Scheduler Operator for Red Hat OpenShift (OSSO)
OpenShift API for Data Protection (OADP)
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
VMware Horizon Client
Dell EMC Container Storage Modules
Red Hat OpenShift GitOps
IBM Data Risk Manager
OpenShift Developer Tools and Services
MySQL Workbench
Oracle Communications Convergent Charging Controller
Splunk Universal Forwarder
Oracle Communications Instant Messaging Server
Cisco Webex Meetings
Splunk Enterprise
Cisco Jabber
Oracle Communications Cloud Native Core Policy
libsqlite3-0 (Ubuntu package)
sqlite3 (Ubuntu package)
sqlite (Red Hat package)
sqlite
sqlite-devel
sqlite-help
sqlite-debuginfo
sqlite-debugsource
dev-db/sqlite
sqlite3-debugsource
libsqlite3-0
libsqlite3-0-32bit
libsqlite3-0-debuginfo
libsqlite3-0-debuginfo-32bit
sqlite3
sqlite3-debuginfo
sqlite3-devel
sqlite3-tcl
sqlite3-doc
libsqlite3-0-32bit-debuginfo
Cloud Pak for Security (CP4S)
Dell EMC Storage Monitoring and Reporting (SMR)
EMC ViPR SRM
Dell EMC VxRail Appliance
PowerScale OneFS
IBM Security Verify Access

How to mitigate CVE-2022-35737

Install updates from vendor's website.

SQLite - update to 3.39.2
Submariner - update to 0.14.0
NetObserv Operator - update to 1.1.0
Self Node Remediation Operator - update to 0.5.1
Secondary Scheduler Operator for Red Hat OpenShift (OSSO) - update to 1.1.1
Migration Toolkit for Runtimes - addressed in versions 1.0.1, 1.0.2
Red Hat OpenShift Serverless - addressed in versions 1.27.0, 1.27.1
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
OpenShift API for Data Protection (OADP) - update to 1.1.2
Migration Toolkit for Containers - addressed in versions 1.7.7, 1.7.10
OpenShift sandboxed containers - update to 1.4.1
Red Hat OpenShift GitOps - addressed in versions 1.5.9, 1.6.4, 1.7, 1.10.0, 1.11
Service Telemetry Framework - update to 1.5.4
IBM Data Risk Manager - update to 2.0.6.15
OpenShift Service Mesh - addressed in versions 2.3.1, 2.3.2
Migration Toolkit for Virtualization - update to 2.4.3
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.6.4, 2.7.0
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.7.0
OpenShift Developer Tools and Services - update to 4.9
Red Hat OpenShift Container Platform - update to 4.13.2
RecoverPoint Classic - update to 5.1 SP4 P4
OpenShift Logging - update to 5.6.1
Red Hat Migration Toolkit for Applications - update to 6.0.1
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
MySQL Workbench - update to 8.0.31
Splunk Universal Forwarder - addressed in versions 8.1.14, 8.2.11, 9.0.5
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
Autodesk Infraworks - addressed in versions 2021.2 Hotfix 9, 2023.1 Hotfix 1
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
libsqlite3-0 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 3.22.0-1ubuntu0.7, 3.31.1-4ubuntu0.5, 3.37.2-2ubuntu0.1
sqlite3 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
cflinuxfs3 - update to 0.332.0
Dell EMC Container Storage Modules - update to 1.6.0
Netcool Operations Insight - update to 1.6.12
Cloud Pak for Security (CP4S) - update to 1.10.12.0
IBM MQ Operator - addressed in versions 2.0.8, 2.3.0
PowerStore T - update to 3.5.0.1-2083289
EMC ECS - update to 3.8.0.2
sqlite (Red Hat package) - addressed in versions 3.26.0-17.el8_7, 3.34.1-6.el9_1
sqlite - update to 3.32.3-6
sqlite-devel - update to 3.32.3-6
sqlite-help - update to 3.32.3-6
sqlite-debuginfo - update to 3.32.3-6
sqlite-debugsource - update to 3.32.3-6
dev-db/sqlite - update to 3.39.2
sqlite3-debugsource - addressed in versions 3.39.3-9.23.1, 3.39.3-150000.3.17.1
libsqlite3-0 - addressed in versions 3.39.3-9.23.1, 3.39.3-150000.3.17.1
libsqlite3-0-32bit - addressed in versions 3.39.3-9.23.1, 3.39.3-150000.3.17.1
libsqlite3-0-debuginfo - addressed in versions 3.39.3-9.23.1, 3.39.3-150000.3.17.1
libsqlite3-0-debuginfo-32bit - update to 3.39.3-9.23.1
sqlite3 - addressed in versions 3.39.3-9.23.1, 3.39.3-150000.3.17.1
sqlite3-debuginfo - addressed in versions 3.39.3-9.23.1, 3.39.3-150000.3.17.1
sqlite3-devel - addressed in versions 3.39.3-9.23.1, 3.39.3-150000.3.17.1
sqlite3-tcl - addressed in versions 3.39.3-9.23.1, 3.39.3-150000.3.17.1
sqlite3-doc - update to 3.39.3-150000.3.17.1
libsqlite3-0-32bit-debuginfo - update to 3.39.3-150000.3.17.1
sqlite - update to 3.40.0-1
Use Case Manager App - update to 4.0.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.6.4
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.8.0.1
EMC ViPR SRM - update to 4.8.0.1
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.0
OpenShift Container Platform for Windows Containers - update to 7.0.0
Dell EMC VxRail Appliance - update to 7.0.411
IBM supplied MQ Advanced container images - addressed in versions 9.3.0.4-r1, 9.3.2.0-r1
PowerScale OneFS - addressed in versions 9.4.0.14, 9.5.0.6
IBM Security Verify Access - update to 10.0.6.0
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.3, 23.0.3

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins