Out-of-Bounds

Affecting sqlite3 package, versions <3.8.7.1-1+deb8u4

Report new vulnerabilities
Do your applications use this vulnerable package? Test your applications

Overview

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "SQLite" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted SQL statement.

References

CVSS Score

9.8
high severity
  • Attack Vector
    Network
  • Attack Complexity
    Low
  • Privileges Required
    None
  • User Interaction
    None
  • Scope
    Unchanged
  • Confidentiality
    High
  • Integrity
    High
  • Availability
    High
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE
CVE-2017-2519
Snyk ID
SNYK-DEBIAN8-SQLITE3-307572
Disclosed
22 May, 2017
Published
22 May, 2017