CVE-2019-5018: Use After Free
An exploitable use after free vulnerability exists in the window function functionality of Sqlite3 3.26.0. A specially crafted SQL command can cause a use after free vulnerability, potentially resulting in remote code execution. An attacker can send a malicious SQL command to trigger this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/sqliteto a version that resolves this vulnerability.Fixed in 3.28.0 - Upgrade
Upgrade
debian/sqlite3to a version that resolves this vulnerability.Fixed in 3.34.1-3Fixed in 3.34.1-3+deb11u1Fixed in 3.40.1-2+deb12u2Fixed in 3.46.1-7+deb13u1Fixed in 3.53.3-1
Event History
Frequently Asked Questions
What is CVE-2019-5018?
CVE-2019-5018 is an exploitable use after free vulnerability in the window function functionality of Sqlite3 3.26.0.
How severe is CVE-2019-5018?
CVE-2019-5018 has a severity rating of 8.1 (high).
Which software versions are affected by CVE-2019-5018?
CVE-2019-5018 affects Sqlite3 version 3.26.0.
How can CVE-2019-5018 be exploited?
CVE-2019-5018 can be exploited by sending a specially crafted SQL command.
What is the remedy for CVE-2019-5018?
The remedy for CVE-2019-5018 is to update to version 3.27.2-2ubuntu0.2 of Sqlite3.