Do your applications use this vulnerable package?
Test your applications
Overview
Affected versions of this package are vulnerable to Use After Free ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature.
Remediation
Upgrade sqlite3
to version or higher.
References
CVSS Score
7.0
medium severity
-
Attack VectorLocal
-
Attack ComplexityHigh
-
Privileges RequiredLow
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityHigh
-
IntegrityHigh
-
AvailabilityHigh
- CVE
- CVE-2020-13630
- CWE
- CWE-416
- Snyk ID
- SNYK-UBUNTU1804-SQLITE3-571696
- Disclosed
- 27 May, 2020
- Published
- 27 May, 2020