First published: Fri Dec 14 2018(Updated: )
Last updated 24 July 2024
Credit: Tencent Blade Team cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
tvOS | <12.1.2 | 12.1.2 |
SQLite | <3.25.3 | |
Google Chrome | <71.0.3578.80 | |
Red Hat Linux | =6.0 | |
Debian GNU/Linux | =8.0 | |
openSUSE | =15.0 | |
openSUSE | =42.3 | |
debian/chromium | 120.0.6099.224-1~deb11u1 131.0.6778.139-1~deb12u1 133.0.6943.98-1~deb12u1 133.0.6943.98-1 | |
debian/sqlite3 | 3.34.1-3 3.34.1-3+deb11u1 3.40.1-2+deb12u1 3.46.1-1 | |
Android | ||
macOS Mojave | <10.14.3 | 10.14.3 |
macOS High Sierra | ||
macOS High Sierra | ||
Apple iOS, iPadOS, and watchOS | <12.1.3 | 12.1.3 |
Apple iOS, iPadOS, and watchOS | <5.1.3 | 5.1.3 |
Apple iCloud | <7.10 | 7.10 |
Apple iTunes | <12.9.3 | 12.9.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2018-20346
The severity of CVE-2018-20346 is high (8.1).
SQLite versions up to and exclusive of 3.25.3 are affected by CVE-2018-20346.
Remote attackers can exploit CVE-2018-20346 by leveraging the ability to run arbitrary SQL statements after crafted changes to FTS3 shadow tables, resulting in arbitrary code execution.
The fixed version for CVE-2018-20346 is 3.25.3.