ALT-PU-2020-2221-1
Closed vulnerabilities
                                                                                    Published: 2021-02-16
Modified: 2023-08-31
                                                                            Modified: 2023-08-31
BDU:2021-00715
Уязвимость системы управления базами данных SQLite, связанная с записью данных за границами буфера в памяти, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
                                                                                        
                                                                                        
                                                                                            Severity: MEDIUM (5.5)
                                                                                        
                                                                                        
                                                                                        
                                                                                        
                                                                                            Vector: AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
                                                                                        
                                                                                        
                                                                                    
                                                                                
                                                                                        
                                                                                        
                                                                                            Severity: MEDIUM (4.6)
                                                                                        
                                                                                        
                                                                                        
                                                                                        
                                                                                            Vector: AV:L/AC:L/Au:S/C:N/I:N/A:C
                                                                                        
                                                                                        
                                                                                    
                                                                                References:
                                                                        
                                                                        
                                                                    
                                                                                    Published: 2021-02-16
Modified: 2023-11-21
                                                                            Modified: 2023-11-21
BDU:2021-00799
Уязвимость реализации функции resetAccumulator() системы управления базами данных SQLite, позволяющая нарушителю вызвать отказ в обслуживании
                                                                                        
                                                                                        
                                                                                            Severity: HIGH (7.5)
                                                                                        
                                                                                        
                                                                                        
                                                                                        
                                                                                            Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
                                                                                        
                                                                                        
                                                                                    
                                                                                
                                                                                        
                                                                                        
                                                                                            Severity: HIGH (7.8)
                                                                                        
                                                                                        
                                                                                        
                                                                                        
                                                                                            Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C
                                                                                        
                                                                                        
                                                                                    
                                                                                References:
                                                                        
                                                                        
                                                                    
                                                                                    Published: 2020-06-06
Modified: 2024-11-21
                                                                            Modified: 2024-11-21
CVE-2020-13871
SQLite 3.32.2 has a use-after-free in resetAccumulator in select.c because the parse tree rewrite for window functions is too late.
                                                                                        
                                                                                        
                                                                                            Severity: MEDIUM (5.0)
                                                                                        
                                                                                        
                                                                                        
                                                                                        
                                                                                            Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P
                                                                                        
                                                                                        
                                                                                    
                                                                                
                                                                                        
                                                                                        
                                                                                            Severity: HIGH (7.5)
                                                                                        
                                                                                        
                                                                                        
                                                                                        
                                                                                            Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
                                                                                        
                                                                                        
                                                                                    
                                                                                References:
                                                                        - https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
 - https://lists.debian.org/debian-lts-announce/2020/08/msg00037.html
 - https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BN32AGQPMHZRNM6P6L5GZPETOWTGXOKP/
 - https://security.gentoo.org/glsa/202007-26
 - https://security.netapp.com/advisory/ntap-20200619-0002/
 - https://www.oracle.com/security-alerts/cpuApr2021.html
 - https://www.oracle.com/security-alerts/cpujan2021.html
 - https://www.sqlite.org/src/info/79eff1d0383179c4
 - https://www.sqlite.org/src/info/c8d3b9f0a750a529
 - https://www.sqlite.org/src/info/cd708fa84d2aaaea
 - https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
 - https://lists.debian.org/debian-lts-announce/2020/08/msg00037.html
 - https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BN32AGQPMHZRNM6P6L5GZPETOWTGXOKP/
 - https://security.gentoo.org/glsa/202007-26
 - https://security.netapp.com/advisory/ntap-20200619-0002/
 - https://www.oracle.com/security-alerts/cpuApr2021.html
 - https://www.oracle.com/security-alerts/cpujan2021.html
 - https://www.sqlite.org/src/info/79eff1d0383179c4
 - https://www.sqlite.org/src/info/c8d3b9f0a750a529
 - https://www.sqlite.org/src/info/cd708fa84d2aaaea
 
                                                                                    Published: 2020-06-27
Modified: 2024-11-21
                                                                            Modified: 2024-11-21
CVE-2020-15358
In SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation.
                                                                                        
                                                                                        
                                                                                            Severity: LOW (2.1)
                                                                                        
                                                                                        
                                                                                        
                                                                                        
                                                                                            Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P
                                                                                        
                                                                                        
                                                                                    
                                                                                
                                                                                        
                                                                                        
                                                                                            Severity: MEDIUM (5.5)
                                                                                        
                                                                                        
                                                                                        
                                                                                        
                                                                                            Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
                                                                                        
                                                                                        
                                                                                    
                                                                                References:
                                                                        - http://seclists.org/fulldisclosure/2020/Dec/32
 - http://seclists.org/fulldisclosure/2020/Nov/19
 - http://seclists.org/fulldisclosure/2020/Nov/20
 - http://seclists.org/fulldisclosure/2020/Nov/22
 - http://seclists.org/fulldisclosure/2021/Feb/14
 - https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
 - https://security.gentoo.org/glsa/202007-26
 - https://security.netapp.com/advisory/ntap-20200709-0001/
 - https://support.apple.com/kb/HT211843
 - https://support.apple.com/kb/HT211844
 - https://support.apple.com/kb/HT211847
 - https://support.apple.com/kb/HT211850
 - https://support.apple.com/kb/HT211931
 - https://support.apple.com/kb/HT212147
 - https://usn.ubuntu.com/4438-1/
 - https://www.oracle.com/security-alerts/cpuApr2021.html
 - https://www.oracle.com/security-alerts/cpuapr2022.html
 - https://www.oracle.com/security-alerts/cpujan2021.html
 - https://www.oracle.com/security-alerts/cpuoct2020.html
 - https://www.sqlite.org/src/info/10fa79d00f8091e5
 - https://www.sqlite.org/src/timeline?p=version-3.32.3&bt=version-3.32.2
 - https://www.sqlite.org/src/tktview?name=8f157e8010
 - http://seclists.org/fulldisclosure/2020/Dec/32
 - http://seclists.org/fulldisclosure/2020/Nov/19
 - http://seclists.org/fulldisclosure/2020/Nov/20
 - http://seclists.org/fulldisclosure/2020/Nov/22
 - http://seclists.org/fulldisclosure/2021/Feb/14
 - https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
 - https://security.gentoo.org/glsa/202007-26
 - https://security.netapp.com/advisory/ntap-20200709-0001/
 - https://support.apple.com/kb/HT211843
 - https://support.apple.com/kb/HT211844
 - https://support.apple.com/kb/HT211847
 - https://support.apple.com/kb/HT211850
 - https://support.apple.com/kb/HT211931
 - https://support.apple.com/kb/HT212147
 - https://usn.ubuntu.com/4438-1/
 - https://www.oracle.com/security-alerts/cpuApr2021.html
 - https://www.oracle.com/security-alerts/cpuapr2022.html
 - https://www.oracle.com/security-alerts/cpujan2021.html
 - https://www.oracle.com/security-alerts/cpuoct2020.html
 - https://www.sqlite.org/src/info/10fa79d00f8091e5
 - https://www.sqlite.org/src/timeline?p=version-3.32.3&bt=version-3.32.2
 - https://www.sqlite.org/src/tktview?name=8f157e8010