First published: Wed May 27 2020(Updated: )
ext/fts3/fts3_snippet.c in SQLite before 3.32.0 has a NULL pointer dereference via a crafted matchinfo() query.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/sqlite | <3.32.0 | 3.32.0 |
debian/sqlite3 | 3.34.1-3 3.34.1-3+deb11u1 3.40.1-2+deb12u1 3.46.1-1 | |
SQLite | <3.32.0 | |
Fedora | =32 | |
Ubuntu | =16.04 | |
Ubuntu | =18.04 | |
Ubuntu | =19.10 | |
Ubuntu | =20.04 | |
netapp cloud backup | ||
netapp solidfire\, enterprise sds \& hci storage node | ||
Brocade Fabric OS | ||
All of | ||
netapp hci compute node firmware | ||
netapp hci compute node | ||
Debian | =9.0 | |
siemens sinec infrastructure network services | <1.0.1.1 | |
oracle communications network charging and control | >=12.0.0<=12.0.3 | |
oracle communications network charging and control | =6.0.1 | |
Oracle Outside In Technology | =8.5.4 | |
Oracle Outside In Technology | =8.5.5 | |
Oracle Sun ZFS Storage Appliance Kit | =8.8 | |
netapp hci compute node firmware | ||
netapp hci compute node |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-13632.
The severity of CVE-2020-13632 is medium (5.5).
The affected software packages are SQLite (version 2.8.17-15 and 2.8.17-15+deb10u1) and sqlite3 (versions 3.27.2-3+deb10u1, 3.27.2-3+deb10u2, 3.34.1-3, 3.40.1-2, and 3.43.2-1).
To fix CVE-2020-13632, update SQLite to version 3.32.0 or later or sqlite3 to a version that is not affected.
You can find more information about CVE-2020-13632 in the references provided: [link1](https://bugs.chromium.org/p/chromium/issues/detail?id=1080459), [link2](https://sqlite.org/src/info/a4dd148928ea65bd), [link3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L7KXQWHIY2MQP4LNM6ODWJENMXYYQYBN/).