7
CVE-2020-13630
- EPSS 1.03%
- Veröffentlicht 27.05.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:01:38
- Erkennungen
ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fedoraproject ≫ Fedora Version 32
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 19.10
Canonical ≫ Ubuntu Linux Version 20.04 SwEdition lts
Netapp ≫ Cloud Backup Version -
Netapp ≫ Solidfire, Enterprise Sds & Hci Storage Node Version -
Brocade ≫ Fabric Operating System Version -
Netapp ≫ Hci Compute Node Firmware Version -
Debian ≫ Debian Linux Version 9.0
Siemens ≫ Sinec Infrastructure Network Services Version < 1.0.1.1
Oracle ≫ Communications Network Charging And Control Version >= 12.0.0 <= 12.0.3
Oracle ≫ Communications Network Charging And Control Version 6.0.1
Oracle ≫ Outside In Technology Version 8.5.4
Oracle ≫ Outside In Technology Version 8.5.5
Oracle ≫ Zfs Storage Appliance Kit Version 8.8
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.03% | 0.592 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7 | 1 | 5.9 |
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 4.4 | 3.4 | 6.4 |
AV:L/AC:M/Au:N/C:P/I:P/A:P
|
CWE-416 Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
https://www.oracle.com/security-alerts/cpujul2020.html
https://www.oracle.com/security-alerts/cpuoct2020.html
https://lists.debian.org/debian-lts-announce/2020/08/msg00037.html
https://usn.ubuntu.com/4394-1/
https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
http://seclists.org/fulldisclosure/2020/Dec/32
http://seclists.org/fulldisclosure/2020/Nov/20
https://support.apple.com/kb/HT211850
https://support.apple.com/kb/HT211931
https://security.gentoo.org/glsa/202007-26
https://security.FreeBSD.org/advisories/FreeBSD-SA-20:22.sqlite.asc
http://seclists.org/fulldisclosure/2020/Nov/19
http://seclists.org/fulldisclosure/2020/Nov/22
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L7KXQWHIY2MQP4LNM6ODWJENMXYYQYBN/
https://support.apple.com/kb/HT211843
https://support.apple.com/kb/HT211844
https://support.apple.com/kb/HT211935
https://support.apple.com/kb/HT211952
https://bugs.chromium.org/p/chromium/issues/detail?id=1080459
https://security.netapp.com/advisory/ntap-20200608-0002/
https://sqlite.org/src/info/0d69f76f0865f962