CVE-2020-13871
HIGH7.5EPSS 2.4%發布日:2020/6/6修改日:2026/4/28
描述
SQLite 3.32.2 has a use-after-free in resetAccumulator in select.c because the parse tree rewrite for window functions is too late.
受影響套件(2)
- Bitnami/sqlite>= 3.32.2, < 3.32.3
- Debian/sqlite3from 0, < 3.32.2-2
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
參考連結(12)
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2020-13871
- WEBhttps://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
- WEBhttps://lists.debian.org/debian-lts-announce/2020/08/msg00037.html
- WEBhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BN32AGQPMHZRNM6P6L5GZPETOWTGXOKP/
- WEBhttps://nvd.nist.gov/vuln/detail/CVE-2020-13871
- WEBhttps://security.gentoo.org/glsa/202007-26
- WEBhttps://security.netapp.com/advisory/ntap-20200619-0002/
- WEBhttps://www.oracle.com/security-alerts/cpuApr2021.html
- WEBhttps://www.oracle.com/security-alerts/cpujan2021.html
- WEBhttps://www.sqlite.org/src/info/79eff1d0383179c4
- WEBhttps://www.sqlite.org/src/info/c8d3b9f0a750a529
- WEBhttps://www.sqlite.org/src/info/cd708fa84d2aaaea