CVE-2020-11655: SQL Injection
Last updated 18 August 2025
Other sources
SQLite through 3.31.1 allows attackers to cause a denial of service (segmentation fault) via a malformed window-function query because the AggInfo object's initialization is mishandled.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/sqlite3to a version that resolves this vulnerability.Fixed in 3.34.1-3Fixed in 3.34.1-3+deb11u1Fixed in 3.40.1-2+deb12u2Fixed in 3.46.1-7+deb13u1Fixed in 3.53.3-1
Event History
Frequently Asked Questions
What is CVE-2020-11655?
CVE-2020-11655 is a vulnerability in SQLite that allows attackers to cause a denial of service (segmentation fault) via a malformed window-function query.
What is the severity of CVE-2020-11655?
The severity of CVE-2020-11655 is high, with a severity value of 7.5.
Which software versions are affected by CVE-2020-11655?
The affected software versions include SQLite 2.8.17-15, SQLite 2.8.17-15+deb10u1, SQLite3 versions 3.27.2-3+deb10u1, 3.27.2-3+deb10u2, 3.34.1-3, 3.40.1-2, 3.43.2-1, and SQLite3 3.31.1-5.
How can I fix CVE-2020-11655?
To fix CVE-2020-11655, update your SQLite and SQLite3 packages to versions that include the necessary security patches.
Where can I find more information about CVE-2020-11655?
You can find more information about CVE-2020-11655 at the following references: [Reference 1](https://www3.sqlite.org/cgi/src/info/4a302b42c7bf5e11), [Reference 2](https://www3.sqlite.org/cgi/src/tktview?name=af4556bb5c), [Reference 3](https://security.netapp.com/advisory/ntap-20200416-0001/).