CVE-2015-3416
24.04.2015, 17:59
The sqlite3VXPrintf function in printf.c in SQLite before 3.8.9 does not properly handle precision and width values during floating-point conversions, which allows context-dependent attackers to cause a denial of service (integer overflow and stack-based buffer overflow) or possibly have unspecified other impact via large integers in a crafted printf function call in a SELECT statement.Enginsight
Vendor | Product | Version |
---|---|---|
canonical | ubuntu_linux | 12.04 |
canonical | ubuntu_linux | 14.04 |
canonical | ubuntu_linux | 15.04 |
sqlite | sqlite | 𝑥 ≤ 3.8.8.3 |
debian | debian_linux | 8.0 |
apple | mac_os_x | 𝑥 ≤ 10.6.8 |
apple | watchos | 𝑥 ≤ 1.0.1 |
php | php | 5.4.0 ≤ 𝑥 < 5.4.42 |
php | php | 5.5.0 ≤ 𝑥 < 5.5.26 |
php | php | 5.6.0 ≤ 𝑥 < 5.6.10 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
sqlite |
| ||||||||||||||||||||||||||||||||||||||||||||||
sqlite3 |
|
References