CVE-2018-8740: Null Pointer Dereference
In SQLite through 3.22.0, databases whose schema is corrupted using a CREATE TABLE AS statement could cause a NULL pointer dereference, related to build.c and prepare.c.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/sqlite3to a version that resolves this vulnerability.Fixed in 3.34.1-3Fixed in 3.34.1-3+deb11u1Fixed in 3.40.1-2+deb12u2Fixed in 3.46.1-7+deb13u1Fixed in 3.46.1-9Fixed in 3.53.3-1
Event History
Frequently Asked Questions
What is CVE-2018-8740?
CVE-2018-8740 is a vulnerability in SQLite through 3.22.0 that can cause a NULL pointer dereference when databases with corrupted schema are used with a CREATE TABLE AS statement.
What is the severity of CVE-2018-8740?
The severity of CVE-2018-8740 is rated as high with a severity value of 7.5.
How does CVE-2018-8740 affect software?
CVE-2018-8740 affects SQLite versions up to and including 3.22.0 and can cause a NULL pointer dereference when databases with corrupted schema are used with a CREATE TABLE AS statement.
What is the remedy for CVE-2018-8740 in Debian?
The remedy for CVE-2018-8740 in Debian is to update to version 3.27.2-3+deb10u1 or higher for SQLite or version 3.27.2-3+deb10u1, 3.27.2-3+deb10u2, 3.34.1-3, 3.40.1-2, or 3.43.2-1 for SQLite3.
What is the remedy for CVE-2018-8740 in Ubuntu?
The remedy for CVE-2018-8740 in Ubuntu is to update to version 3.22.0-1ubuntu0.4 for SQLite3 in Bionic, version 3.8.2-1ubuntu2.2 for SQLite3 in Trusty, version 3.22.0-2 for SQLite3 with upstream, or version 3.11.0-1ubuntu1.1 for SQLite3 in Xenial.