5.5

CVE-2020-13434

Exploit
SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sqlite ≫ Sqlite Version <= 3.32.0
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Fedoraproject ≫ Fedora Version 32
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 19.10
Canonical ≫ Ubuntu Linux Version 20.04 SwEdition lts
Freebsd ≫ Freebsd Version >= 11.0 < 11.4
Freebsd ≫ Freebsd Version 11.4 Update -
Freebsd ≫ Freebsd Version 11.4 Update p1
Freebsd ≫ Freebsd Version 12.0 Update -
Freebsd ≫ Freebsd Version 12.0 Update p1
Freebsd ≫ Freebsd Version 12.0 Update p10
Freebsd ≫ Freebsd Version 12.0 Update p11
Freebsd ≫ Freebsd Version 12.0 Update p12
Freebsd ≫ Freebsd Version 12.0 Update p2
Freebsd ≫ Freebsd Version 12.0 Update p3
Freebsd ≫ Freebsd Version 12.0 Update p4
Freebsd ≫ Freebsd Version 12.0 Update p5
Freebsd ≫ Freebsd Version 12.0 Update p6
Freebsd ≫ Freebsd Version 12.0 Update p7
Freebsd ≫ Freebsd Version 12.0 Update p8
Freebsd ≫ Freebsd Version 12.0 Update p9
Freebsd ≫ Freebsd Version 12.1 Update -
Freebsd ≫ Freebsd Version 12.1 Update p1
Freebsd ≫ Freebsd Version 12.1 Update p2
Freebsd ≫ Freebsd Version 12.1 Update p3
Freebsd ≫ Freebsd Version 12.1 Update p4
Freebsd ≫ Freebsd Version 12.1 Update p5
Freebsd ≫ Freebsd Version 12.1 Update p6
Freebsd ≫ Freebsd Version 12.1 Update p7
Oracle ≫ Communications Network Charging And Control Version >= 12.0.0 <= 12.0.3
Oracle ≫ Outside In Technology Version 8.5.5
Apple ≫ iCloud SwPlatform windows Version < 11.5
Apple ≫ iTunes SwPlatform windows Version < 12.10.9
Apple ≫ iPadOS Version < 14.0
Apple ≫ iPhone OS Version < 14.0
Apple ≫ macOS Version >= 11.0 < 11.0.1
Apple ≫ tvOS Version < 14.0
Apple ≫ watchOS Version < 7.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.01% 0.603
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:N/I:N/A:P
CWE-190 Integer Overflow or Wraparound

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

https://www.oracle.com/security-alerts/cpuapr2022.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2020.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpuApr2021.html
Patch
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2020/08/msg00037.html
Third Party Advisory
Mailing List
https://usn.ubuntu.com/4394-1/
Third Party Advisory
http://seclists.org/fulldisclosure/2020/Dec/32
Third Party Advisory
Mailing List
http://seclists.org/fulldisclosure/2020/Nov/20
Third Party Advisory
Mailing List
https://support.apple.com/kb/HT211850
Third Party Advisory
https://support.apple.com/kb/HT211931
Third Party Advisory
https://security.gentoo.org/glsa/202007-26
Third Party Advisory
https://security.FreeBSD.org/advisories/FreeBSD-SA-20:22.sqlite.asc
Third Party Advisory
http://seclists.org/fulldisclosure/2020/Nov/19
Third Party Advisory
Mailing List
http://seclists.org/fulldisclosure/2020/Nov/22
Third Party Advisory
Mailing List
https://lists.debian.org/debian-lts-announce/2020/05/msg00024.html
Third Party Advisory
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L7KXQWHIY2MQP4LNM6ODWJENMXYYQYBN/
https://security.netapp.com/advisory/ntap-20200528-0004/
Third Party Advisory
https://support.apple.com/kb/HT211843
Third Party Advisory
https://support.apple.com/kb/HT211844
Third Party Advisory
https://support.apple.com/kb/HT211935
Third Party Advisory
https://support.apple.com/kb/HT211952
Third Party Advisory
https://www.sqlite.org/src/info/23439ea582241138
Patch
Vendor Advisory
Exploit
https://www.sqlite.org/src/info/d08d3405878d394e
Patch
Vendor Advisory