CVE-2019-9936
22.03.2019, 08:29
In SQLite 3.27.2, running fts5 prefix queries inside a transaction could trigger a heap-based buffer over-read in fts5HashEntrySort in sqlite3.c, which may lead to an information leak. This is related to ext/fts5/fts5_hash.c.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| sqlite | sqlite | 3.27.2 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libsqlite3-0 |
| ||||||||||||||||||||||||||||||||||||||||||||||||
| libsqlite3-0-32bit |
| ||||||||||||||||||||||||||||||||||||||||||||||||
| sqlite3 |
| ||||||||||||||||||||||||||||||||||||||||||||||||
| sqlite3-devel |
| ||||||||||||||||||||||||||||||||||||||||||||||||
| sqlite3-tcl |
|
Common Weakness Enumeration
References