CVE-2020-9327: Null Pointer Dereference
In SQLite 3.31.1, isAuxiliaryVtabOperator allows attackers to trigger a NULL pointer dereference and segmentation fault because of generated column optimizations.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/sqlite3to a version that resolves this vulnerability.Fixed in 3.34.1-3Fixed in 3.34.1-3+deb11u1Fixed in 3.40.1-2+deb12u2Fixed in 3.46.1-7+deb13u1Fixed in 3.46.1-9Fixed in 3.53.3-1 - Upgrade
Upgrade
sqliteto a version that resolves this vulnerability.Fixed in 3.31.1Patch 4374860b29383380 - Upgrade
Upgrade
sqliteto a version that resolves this vulnerability.Fixed in 3.31.1Patch 9d0d4ab95dc0c56e - Upgrade
Upgrade
sqliteto a version that resolves this vulnerability.Fixed in 3.31.1Patch abc473fb8fb99900
Event History
Frequently Asked Questions
What is CVE-2020-9327?
CVE-2020-9327 is a vulnerability in SQLite 3.31.1 that allows attackers to trigger a NULL pointer dereference and segmentation fault.
What is the severity of CVE-2020-9327?
The severity of CVE-2020-9327 is high with a severity value of 7.5.
Which software versions are affected by CVE-2020-9327?
CVE-2020-9327 affects SQLite 3.22.0-1ubuntu0.3, 3.29.0-2ubuntu0.2, 3.31.1-3, and other versions.
How can I fix CVE-2020-9327?
To fix CVE-2020-9327, update to a version of SQLite that is not affected by the vulnerability.
Where can I find more information about CVE-2020-9327?
You can find more information about CVE-2020-9327 on the CERT-Portal Siemens, Gentoo Security, and Netapp Security websites.