CVE-2024-0232
16.01.2024, 14:15
A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service.Enginsight
| Vendor | Product | Version |
|---|---|---|
| sqlite | sqlite | 3.43.0 ≤ 𝑥 < 3.43.2 |
| redhat | enterprise_linux | 8.0 |
| redhat | enterprise_linux | 9.0 |
| fedoraproject | extra_packages_for_enterprise_linux | 8.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| sqlite |
| ||||||||||||||||||||||
| sqlite3 |
|
Common Weakness Enumeration
References