First published: Fri Jul 07 2017(Updated: )
Last updated 24 July 2024
Credit: found by OSS-Fuzz found by OSS-Fuzz found by OSS-Fuzz found by OSS-Fuzz found by OSS-Fuzz found by OSS-Fuzz found by OSS-Fuzz found by OSS-Fuzz found by OSS-Fuzz found by OSS-Fuzz found by OSS-Fuzz found by OSS-Fuzz found by OSS-Fuzz found by OSS-Fuzz found by OSS-Fuzz found by OSS-Fuzz cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SQLite SQLite | <=3.19.3 | |
Apple macOS High Sierra | <10.13 | 10.13 |
Apple watchOS | <4 | 4 |
Apple tvOS | <11 | 11 |
Apple iOS | <11 | 11 |
F5 Traffix SDC | =5.1.0 | |
debian/sqlite3 | 3.34.1-3 3.34.1-3+deb11u1 3.40.1-2+deb12u1 3.46.1-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-10989 is a vulnerability in SQLite through version 3.19.3 that mishandles undersized RTree blobs in a crafted database, leading to a heap-based buffer over-read or other unspecified impact.
CVE-2017-10989 has a severity score of 9.8 (Critical).
Software products such as GDAL, Debian SQLite, Debian SQLite3, Ubuntu SQLite3, Apple macOS High Sierra, Apple tvOS, Apple iOS, and Apple watchOS are affected by CVE-2017-10989.
To fix CVE-2017-10989, update SQLite to version 3.19.3 or higher.
You can find more information about CVE-2017-10989 on the following references: [1] http://marc.info/?l=sqlite-users&m=149933696214713&w=2, [2] https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=2405, [3] https://bugs.launchpad.net/ubuntu/+source/sqlite3/+bug/1700937