CVE-2024-0232
16.01.2024, 14:15
A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service.Enginsight
Vendor | Product | Version |
---|---|---|
sqlite | sqlite | 3.43.0 ≤ 𝑥 < 3.43.2 |
redhat | enterprise_linux | 8.0 |
redhat | enterprise_linux | 9.0 |
fedoraproject | extra_packages_for_enterprise_linux | 8.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
sqlite |
| ||||||||||||||||||||
sqlite3 |
|
Common Weakness Enumeration
References