CVE-2015-3415
24.04.2015, 17:59
The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly implement comparison operators, which allows context-dependent attackers to cause a denial of service (invalid free operation) or possibly have unspecified other impact via a crafted CHECK clause, as demonstrated by CHECK(0&O>O) in a CREATE TABLE statement.Enginsight
Vendor | Product | Version |
---|---|---|
apple | mac_os_x | 10.10.5 |
apple | watchos | 1.0.1 |
debian | debian_linux | 8.0 |
canonical | ubuntu_linux | 12.04 |
canonical | ubuntu_linux | 14.04 |
canonical | ubuntu_linux | 15.04 |
sqlite | sqlite | 𝑥 ≤ 3.8.8.3 |
php | php | 5.4.0 ≤ 𝑥 < 5.4.42 |
php | php | 5.5.0 ≤ 𝑥 < 5.5.26 |
php | php | 5.6.0 ≤ 𝑥 < 5.6.10 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
sqlite |
| ||||||||||||||||||||||||
sqlite3 |
|
Common Weakness Enumeration
References