First published: Fri Feb 21 2020(Updated: )
In SQLite 3.31.1, isAuxiliaryVtabOperator allows attackers to trigger a NULL pointer dereference and segmentation fault because of generated column optimizations.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/sqlite3 | 3.34.1-3 3.34.1-3+deb11u1 3.40.1-2 3.46.0-1 3.46.1-1 | |
SQLite | =3.31.1 | |
NetApp Cloud Backup | ||
Ubuntu | =16.04 | |
Ubuntu | =18.04 | |
Ubuntu | =19.10 | |
Siemens SINEC Infrastructure Network Services | <1.0.1.1 | |
Oracle Communications Network Charging and Control | >=12.0.0<=12.0.3 | |
Oracle Communications Network Charging and Control | =6.0.1 | |
Oracle Communications Network Charging and Control | =12.0.2 | |
Oracle Enterprise Manager Ops Center | =12.4.0.0 | |
Oracle Hyperion Infrastructure Technology | =11.1.2.4 | |
MySQL Workbench | <=8.0.22 | |
Oracle Outside In Technology | =8.5.4 | |
Oracle Outside In Technology | =8.5.5 | |
Oracle Storage Cloud Software Appliance | =8.8 | |
Sun iPlanet Messaging Server | =8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9327 is a vulnerability in SQLite 3.31.1 that allows attackers to trigger a NULL pointer dereference and segmentation fault.
The severity of CVE-2020-9327 is high with a severity value of 7.5.
CVE-2020-9327 affects SQLite 3.22.0-1ubuntu0.3, 3.29.0-2ubuntu0.2, 3.31.1-3, and other versions.
To fix CVE-2020-9327, update to a version of SQLite that is not affected by the vulnerability.
You can find more information about CVE-2020-9327 on the CERT-Portal Siemens, Gentoo Security, and Netapp Security websites.