CVE-2020-13434
MEDIUM5.5EPSS 0.06%sqlite3 - security update
發布日:2020/5/24修改日:2026/4/28
描述
SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c.
受影響套件(4)
- Alpine/sqlitefrom 0, < 3.32.1-r0
- Bitnami/sqlitefrom 0, < 3.32.1
- Debian/sqlite3from 0, < 3.32.1-1
- Debian/sqlite3from 0, < 3.8.7.1-1+deb8u6
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.5 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
參考連結(25)
- ADVISORYhttps://security.alpinelinux.org/vuln/CVE-2020-13434
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2020-13434
- WEBhttp://seclists.org/fulldisclosure/2020/Dec/32
- WEBhttp://seclists.org/fulldisclosure/2020/Nov/19
- WEBhttp://seclists.org/fulldisclosure/2020/Nov/20
- WEBhttp://seclists.org/fulldisclosure/2020/Nov/22
- WEBhttps://lists.debian.org/debian-lts-announce/2020/05/msg00024.html
- WEBhttps://lists.debian.org/debian-lts-announce/2020/08/msg00037.html
- WEBhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L7KXQWHIY2MQP4LNM6ODWJENMXYYQYBN/
- WEBhttps://nvd.nist.gov/vuln/detail/CVE-2020-13434
- WEBhttps://security.FreeBSD.org/advisories/FreeBSD-SA-20:22.sqlite.asc
- WEBhttps://security.gentoo.org/glsa/202007-26
- WEBhttps://security.netapp.com/advisory/ntap-20200528-0004/
- WEBhttps://support.apple.com/kb/HT211843
- WEBhttps://support.apple.com/kb/HT211844
- WEBhttps://support.apple.com/kb/HT211850
- WEBhttps://support.apple.com/kb/HT211931
- WEBhttps://support.apple.com/kb/HT211935
- WEBhttps://support.apple.com/kb/HT211952
- WEBhttps://usn.ubuntu.com/4394-1/
- WEBhttps://www.oracle.com/security-alerts/cpuApr2021.html
- WEBhttps://www.oracle.com/security-alerts/cpuapr2022.html
- WEBhttps://www.oracle.com/security-alerts/cpujul2020.html
- WEBhttps://www.sqlite.org/src/info/23439ea582241138
- WEBhttps://www.sqlite.org/src/info/d08d3405878d394e