CVE-2020-13632: Null Pointer Dereference
ext/fts3/fts3snippet.c in SQLite before 3.32.0 has a NULL pointer dereference via a crafted matchinfo() query.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/sqliteto a version that resolves this vulnerability.Fixed in 3.32.0 - Upgrade
Upgrade
debian/sqlite3to a version that resolves this vulnerability.Fixed in 3.34.1-3Fixed in 3.34.1-3+deb11u1Fixed in 3.40.1-2+deb12u2Fixed in 3.46.1-7+deb13u1Fixed in 3.53.3-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.2.1-1 - Upgrade
Upgrade
sqliteto a version that resolves this vulnerability.Fixed in 3.32.0
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-13632.
What is the severity of CVE-2020-13632?
The severity of CVE-2020-13632 is medium (5.5).
What software packages are affected by CVE-2020-13632?
The affected software packages are SQLite (version 2.8.17-15 and 2.8.17-15+deb10u1) and sqlite3 (versions 3.27.2-3+deb10u1, 3.27.2-3+deb10u2, 3.34.1-3, 3.40.1-2, and 3.43.2-1).
How do I fix CVE-2020-13632?
To fix CVE-2020-13632, update SQLite to version 3.32.0 or later or sqlite3 to a version that is not affected.
Where can I find more information about CVE-2020-13632?
You can find more information about CVE-2020-13632 in the references provided: [link1](https://bugs.chromium.org/p/chromium/issues/detail?id=1080459), [link2](https://sqlite.org/src/info/a4dd148928ea65bd), [link3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L7KXQWHIY2MQP4LNM6ODWJENMXYYQYBN/).