First published: Fri Dec 14 2018(Updated: )
Last updated 24 July 2024
Credit: Tencent Blade Team Tencent Blade Team Tencent Blade Team Tencent Blade Team Tencent Blade Team Tencent Blade Team Tencent Blade Team Tencent Blade Team Tencent Blade Team Tencent Blade Team Tencent Blade Team Tencent Blade Team Tencent Blade Team Tencent Blade Team Tencent Blade Team Tencent Blade Team Tencent Blade Team Tencent Blade Team cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iCloud for Windows | <7.10 | 7.10 |
Apple iTunes for Windows | <12.9.3 | 12.9.3 |
SQLite SQLite | <3.25.3 | |
Google Chrome | <71.0.3578.80 | |
Redhat Linux | =6.0 | |
Debian Debian Linux | =8.0 | |
openSUSE Leap | =15.0 | |
openSUSE Leap | =42.3 | |
Apple watchOS | <5.1.3 | 5.1.3 |
Apple macOS Mojave | <10.14.3 | 10.14.3 |
Apple High Sierra | ||
Apple Sierra | ||
Apple tvOS | <12.1.2 | 12.1.2 |
Apple iOS | <12.1.3 | 12.1.3 |
Google Android | ||
debian/chromium | 120.0.6099.224-1~deb11u1 130.0.6723.91-1~deb12u1 131.0.6778.204-1~deb12u1 131.0.6778.139-1 131.0.6778.204-1 | |
debian/sqlite3 | 3.34.1-3 3.34.1-3+deb11u1 3.40.1-2+deb12u1 3.46.1-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2018-20346
The severity of CVE-2018-20346 is high (8.1).
SQLite versions up to and exclusive of 3.25.3 are affected by CVE-2018-20346.
Remote attackers can exploit CVE-2018-20346 by leveraging the ability to run arbitrary SQL statements after crafted changes to FTS3 shadow tables, resulting in arbitrary code execution.
The fixed version for CVE-2018-20346 is 3.25.3.