#VU27024 Use-after-free in SQLite - CVE-2020-11656
Published: April 20, 2020 / Updated: October 28, 2023
SQLite
SQLite
Description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error in the ALTER TABLE implementation. A remote attacker can execute arbitrary code on the target system, as demonstrated by an ORDER BY clause that belongs to a compound SELECT statement.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.