CVE-2015-3415
EPSS 4.9%
描述
The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly implement comparison operators, which allows context-dependent attackers to cause a denial of service (invalid free operation) or possibly have unspecified other impact via a crafted CHECK clause, as demonstrated by CHECK(0&O>O) in a CREATE TABLE statement.
如何修補 CVE-2015-3415
要修補 CVE-2015-3415,請將受影響套件升級到下列已修補版本。
- Debian/sqlite3—升級至 3.8.9-1 或更新版本
CVE-2015-3415 正在被利用嗎?
低 — EPSS 為 4.9%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 3.8.9-1