Use-after-free in SQLite - CVE-2024-0232

 

Use-after-free in SQLite - CVE-2024-0232

Published: March 6, 2024


Vulnerability identifier: #VU87160
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-0232
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a use-after-free error within the jsonParseAddNodeArray() function in sqlite3.c. A remote attacker can pass specially crafted json data to the application and perform a denial of service (DoS) attack.


Affected software

SQLite
Netezza Appliance
Oracle Communications Network Charging and Control
webMethods Managed File Transfer
Cloud Pak for Data System - Cyclops
Voice Gateway
Oracle Communications Instant Messaging Server
Nessus Network Monitor
Oracle Communications Convergent Charging Controller
Oracle Financial Services Compliance Studio
PeopleSoft Enterprise PeopleTools
Fedora
Tivoli Composite Application Manager for Transactions
chromium

How to mitigate CVE-2024-0232

Install updates from vendor's website.

SQLite - update to 3.43.2
Netezza Appliance - update to 1.0.0.1
Voice Gateway - update to 1.0.8.12
Nessus Network Monitor - update to 6.5.3
Tivoli Composite Application Manager for Transactions - update to 7.4.0.2.24
Cloud Pak for Data System - Cyclops - update to 11.3.1.1
chromium - update to 122.0.6261.57-1.fc39

External References

Related Security Bulletins