multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsing, as demonstrated by errors from sqlite3WindowRewrite() calls. NOTE: this vulnerability exists because of an incomplete fix for CVE-2019-19880.
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Sqlite | Sqlite | 3.30.1 (including) | 3.30.1 (including) |
Red Hat Enterprise Linux 6 Supplementary | RedHat | chromium-browser-0:80.0.3987.87-1.el6_10 | * |
Sqlite3 | Ubuntu | bionic | * |
Sqlite3 | Ubuntu | disco | * |
Sqlite3 | Ubuntu | eoan | * |
Sqlite3 | Ubuntu | precise/esm | * |
Sqlite3 | Ubuntu | trusty | * |
Sqlite3 | Ubuntu | trusty/esm | * |
Sqlite3 | Ubuntu | xenial | * |