Memory leak in SQLite - CVE-2021-45346

 

Memory leak in SQLite - CVE-2021-45346

Published: September 15, 2022 / Updated: October 12, 2022


Vulnerability identifier: #VU67415
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-45346
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform DoS attack on the target system.

The vulnerability exists due memory leak. A remote attacker can force the application to leak memory and perform denial of service attack.


Affected software

SQLite
Tivoli Composite Application Manager for Transactions
IBM Cloud Application Performance Management (APM)

How to mitigate CVE-2021-45346

Install updates from vendor's website.

SQLite - update to 3.37.1
Tivoli Composite Application Manager for Transactions - addressed in versions 7.4.0.1.59, 7.4.0.2.18
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.13

External References

Related Security Bulletins