Buffer overflow in SQLite - CVE-2020-24736

 

Buffer overflow in SQLite - CVE-2020-24736

Published: June 29, 2023


Vulnerability identifier: #VU77780
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-24736
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error when executing a crafted SELECT query. A local user can execute a specially crafted query to trigger memory corruption and perform a denial of service (DoS) attack.


Affected software

SQLite
Oracle Linux
Red Hat Enterprise Linux for IBM z Systems
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Gatekeeper Operator
VolSync
Run Once Duration Override Operator for Red Hat OpenShift
Red Hat CodeReady Workspaces for OpenShift
Service Telemetry Framework
Migration Toolkit for Virtualization
Red Hat Advanced Cluster Management for Kubernetes
Red Hat OpenShift Dev Spaces
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Red Hat OpenStack
Netcool Operations Insight
IBM MQ Operator
Red Hat Advanced Cluster Security for Kubernetes
App Connect Enterprise Certified Container
Node Health Check Operator
Self Node Remediation Operator
OpenShift sandboxed containers
Red Hat OpenShift Serverless
Multicluster Engine for Kubernetes
OpenShift Service Mesh
OpenShift Data Foundation (formerly OpenShift Container Storage)
Node Maintenance Operator
OpenShift Container Platform for Windows Containers
OpenShift Virtualization
Secondary Scheduler Operator for Red Hat OpenShift (OSSO)
OpenShift API for Data Protection (OADP)
Migration Toolkit for Containers
AMQ Broker
Red Hat OpenShift GitOps
sqlite-libs
sqlite-devel
sqlite
lemon
sqlite-doc
sqlite (Red Hat package)
IBM Cloud Pak for Watson AIOps
Robotic Process Automation for Cloud Pak

How to mitigate CVE-2020-24736

Install updates from vendor's website.

Node Health Check Operator - update to 0.4.1
VolSync - addressed in versions 0.5.4, 0.6.3, 0.7.3
Self Node Remediation Operator - update to 0.5.1
Run Once Duration Override Operator for Red Hat OpenShift - update to 1.0.1
Secondary Scheduler Operator for Red Hat OpenShift (OSSO) - update to 1.1.2
OpenShift API for Data Protection (OADP) - addressed in versions 1.0.11, 1.1.6
OpenShift sandboxed containers - update to 1.4.1
Service Telemetry Framework - update to 1.5.4
Migration Toolkit for Containers - addressed in versions 1.7.11, 1.7.12
Red Hat OpenShift Serverless - update to 1.29.1
Multicluster Engine for Kubernetes - addressed in versions 2.1.8, 2.2.7
OpenShift Service Mesh - addressed in versions 2.2.8, 2.2.10, 2.3.5, 2.4.1
Migration Toolkit for Virtualization - update to 2.4.3
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.6.7, 2.7.7, 2.8.1
Red Hat OpenShift Dev Spaces - update to 3.7.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.10.14, 4.11.9, 4.12.5
Node Maintenance Operator - update to 5.0.1
OpenShift Container Platform for Windows Containers - update to 6.0.1
AMQ Broker - update to 7.11.1
Netcool Operations Insight - update to 1.6.12
Red Hat OpenShift GitOps - addressed in versions 1.10.0, 1.11
IBM MQ Operator - addressed in versions 2.0.13, 2.4.1
sqlite-libs - update to 3.26.0-18
sqlite-devel - update to 3.26.0-18
sqlite - update to 3.26.0-18
lemon - update to 3.26.0-18
sqlite-doc - update to 3.26.0-18
sqlite (Red Hat package) - update to 3.26.0-18.el8_8
Red Hat Advanced Cluster Security for Kubernetes - update to 4.1
IBM Cloud Pak for Watson AIOps - update to 4.2.0
OpenShift Virtualization - update to 4.12.5
App Connect Enterprise Certified Container - addressed in versions 5.0.9, 9.1.0
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.11, 23.0.12

External References

Related Security Bulletins