First published: Wed May 27 2020(Updated: )
ext/fts3/fts3_snippet.c in SQLite before 3.32.0 has a NULL pointer dereference via a crafted matchinfo() query.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/sqlite | <3.32.0 | 3.32.0 |
SQLite SQLite | <3.32.0 | |
Fedoraproject Fedora | =32 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =19.10 | |
Canonical Ubuntu Linux | =20.04 | |
Netapp Cloud Backup | ||
Netapp Solidfire\, Enterprise Sds \& Hci Storage Node | ||
Brocade Fabric Operating System | ||
Netapp Hci Compute Node Firmware | ||
Netapp Hci Compute Node | ||
Debian Debian Linux | =9.0 | |
Siemens Sinec Infrastructure Network Services | <1.0.1.1 | |
Oracle Communications Network Charging And Control | >=12.0.0<=12.0.3 | |
Oracle Communications Network Charging And Control | =6.0.1 | |
Oracle Outside In Technology | =8.5.4 | |
Oracle Outside In Technology | =8.5.5 | |
Oracle ZFS Storage Appliance Kit | =8.8 | |
All of | ||
Netapp Hci Compute Node Firmware | ||
Netapp Hci Compute Node | ||
debian/sqlite3 | 3.34.1-3 3.34.1-3+deb11u1 3.40.1-2+deb12u1 3.46.1-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-13632.
The severity of CVE-2020-13632 is medium (5.5).
The affected software packages are SQLite (version 2.8.17-15 and 2.8.17-15+deb10u1) and sqlite3 (versions 3.27.2-3+deb10u1, 3.27.2-3+deb10u2, 3.34.1-3, 3.40.1-2, and 3.43.2-1).
To fix CVE-2020-13632, update SQLite to version 3.32.0 or later or sqlite3 to a version that is not affected.
You can find more information about CVE-2020-13632 in the references provided: [link1](https://bugs.chromium.org/p/chromium/issues/detail?id=1080459), [link2](https://sqlite.org/src/info/a4dd148928ea65bd), [link3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L7KXQWHIY2MQP4LNM6ODWJENMXYYQYBN/).