CVE-2019-8457: SQL Injection
Last updated 11 July 2025
Other sources
SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree tables.
Upstream commit: https://www.sqlite.org/src/info/90acdbfce9c08858
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this SQLite3 vulnerability?
The vulnerability ID for this SQLite3 vulnerability is CVE-2019-8457.
What is the severity level of CVE-2019-8457?
CVE-2019-8457 has a severity level of critical.
Which software versions are affected by CVE-2019-8457?
SQLite3 versions from 3.6.0 to and including 3.27.2 are affected by CVE-2019-8457.
What is the impact of CVE-2019-8457?
CVE-2019-8457 can lead to a heap out-of-bound read vulnerability in the rtreenode() function of SQLite3, potentially allowing attackers to read sensitive information.
Are there any fix or remedy available for CVE-2019-8457?
Yes, there are remedies available depending on the affected software versions. Please refer to the official references for more information on the fixes.