First published: Wed May 27 2020(Updated: )
ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature.
Credit: cve@mitre.org CVE-2020-13630
Affected Software | Affected Version | How to fix |
---|---|---|
<3.32.0 | ||
=32 | ||
=16.04 | ||
=18.04 | ||
=19.10 | ||
=20.04 | ||
=9.0 | ||
<1.0.1.1 | ||
<11.5 | ||
<12.10.9 | ||
<14.0 | ||
<14.0 | ||
<11.0.1 | ||
<14.0 | ||
<7.0 | ||
>=12.0.0<=12.0.3 | ||
=6.0.1 | ||
=8.5.4 | ||
=8.5.5 | ||
=8.8 | ||
Apple iCloud for Windows | <11.5 | 11.5 |
Apple iTunes for Windows | <12.10.9 | 12.10.9 |
redhat/sqlite | <3.32.0 | 3.32.0 |
debian/sqlite3 | 3.34.1-3 3.34.1-3+deb11u1 3.40.1-2+deb12u1 3.46.1-1 | |
Apple macOS | <11.0.1 | 11.0.1 |
F5 Traffix Systems Signaling Delivery Controller | =5.1.0 | |
watchOS | <7.0 | 7.0 |
tvOS | <14.0 | 14.0 |
Apple iOS | <14.0 | 14.0 |
iPadOS | <14.0 | 14.0 |
SQLite | <3.32.0 | |
Fedoraproject Fedora | =32 | |
Ubuntu Linux | =16.04 | |
Ubuntu Linux | =18.04 | |
Ubuntu Linux | =19.10 | |
Ubuntu Linux | =20.04 | |
netapp cloud backup | ||
netapp solidfire\, enterprise sds \& hci storage node | ||
brocade fabric operating system | ||
All of | ||
netapp hci compute node firmware | ||
netapp hci compute node | ||
Debian GNU/Linux | =9.0 | |
siemens sinec infrastructure network services | <1.0.1.1 | |
apple icloud windows | <11.5 | |
apple itunes windows | <12.10.9 | |
iPadOS | <14.0 | |
Apple iPhone OS | <14.0 | |
Apple macOS | <11.0.1 | |
tvOS | <14.0 | |
watchOS | <7.0 | |
oracle communications network charging and control | >=12.0.0<=12.0.3 | |
oracle communications network charging and control | =6.0.1 | |
Oracle Outside In Technology | =8.5.4 | |
Oracle Outside In Technology | =8.5.5 | |
Oracle Sun ZFS Storage Appliance Kit | =8.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
The vulnerability ID is CVE-2020-13630.
The affected software includes Apple tvOS 14.0, macOS Big Sur 11.0.1, iOS 14.0, iPadOS 14.0, watchOS 7.0, iTunes for Windows 12.10.9, and iCloud for Windows 11.5.
The severity of CVE-2020-13630 is not specified.
The remediation for CVE-2020-13630 is to update to the specified versions of the affected software.
You can find more information about CVE-2020-13630 on the Apple support website.