CVE-2015-3414
24.04.2015, 17:59
SQLite before 3.8.9 does not properly implement the dequoting of collation-sequence names, which allows context-dependent attackers to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other impact via a crafted COLLATE clause, as demonstrated by COLLATE"""""""" at the end of a SELECT statement.Enginsight
Vendor | Product | Version |
---|---|---|
sqlite | sqlite | 𝑥 ≤ 3.8.8.3 |
apple | mac_os_x | 10.10.5 |
apple | watchos | 1.0.1 |
debian | debian_linux | 8.0 |
canonical | ubuntu_linux | 12.04 |
canonical | ubuntu_linux | 14.04 |
canonical | ubuntu_linux | 15.04 |
php | php | 5.4.0 ≤ 𝑥 < 5.4.42 |
php | php | 5.5.0 ≤ 𝑥 < 5.5.26 |
php | php | 5.6.0 ≤ 𝑥 < 5.6.10 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References