CVE Vulnerabilities

CVE-2021-36690

Published: Aug 24, 2021 | Modified: May 17, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
NEGLIGIBLE

A segmentation fault can occur in the sqlite3.exe command-line component of SQLite 3.36.0 via the idxGetTableInfo function when there is a crafted SQL query. NOTE: the vendor disputes the relevance of this report because a sqlite3.exe user already has full privileges (e.g., is intentionally allowed to execute commands). This report does NOT imply any problem in the SQLite library.

Affected Software

Name Vendor Start Version End Version
Sqlite Sqlite 3.36.0 (including) 3.36.0 (including)
Sqlite Ubuntu hirsute *
Sqlite3 Ubuntu bionic *
Sqlite3 Ubuntu focal *
Sqlite3 Ubuntu hirsute *
Sqlite3 Ubuntu impish *
Sqlite3 Ubuntu upstream *

References