CVE-2021-20227
MEDIUM5.5EPSS 0.77%發布日:2021/3/23修改日:2026/4/28
也稱為:ALPINE-CVE-2021-20227DEBIAN-CVE-2021-20227
描述
A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on the SQLite database to cause a denial of service or possible code execution by triggering a use-after-free. The highest threat from this vulnerability is to system availability.
受影響套件(3)
- Alpine/sqlitefrom 0, < 3.32.1-r1
- Bitnami/sqlite>= 3.33.0, < 3.34.1
- Debian/sqlite3from 0, < 3.34.1-1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.5 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
參考連結(11)
- ADVISORYhttps://security.alpinelinux.org/vuln/CVE-2021-20227
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2021-20227
- WEBhttps://bugzilla.redhat.com/show_bug.cgi?id=1924886
- WEBhttps://nvd.nist.gov/vuln/detail/CVE-2021-20227
- WEBhttps://security.gentoo.org/glsa/202103-04
- WEBhttps://security.gentoo.org/glsa/202210-40
- WEBhttps://security.netapp.com/advisory/ntap-20210423-0010/
- WEBhttps://www.oracle.com/security-alerts/cpuApr2021.html
- WEBhttps://www.oracle.com//security-alerts/cpujul2021.html
- WEBhttps://www.oracle.com/security-alerts/cpuoct2021.html
- WEBhttps://www.sqlite.org/releaselog/3_34_1.html