CVE Vulnerabilities

CVE-2019-19880

NULL Pointer Dereference

Published: Dec 18, 2019 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values in ORDER BY clauses of window definitions are mishandled.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
SqliteSqlite3.30.1 (including)3.30.1 (including)
Red Hat Enterprise Linux 6 SupplementaryRedHatchromium-browser-0:80.0.3987.87-1.el6_10*
Sqlite3Ubuntudisco*
Sqlite3Ubuntueoan*
Sqlite3Ubuntutrusty*

Potential Mitigations

References