CVE-2021-3119: Null Pointer Dereference
Zetetic SQLCipher 4.x before 4.4.3 has a NULL pointer dereferencing issue related to sqlcipherexport in crypto.c and sqlite3StrICmp in sqlite3.c. This may allow an attacker to perform a remote denial of service attack. For example, an SQL injection can be used to execute the crafted SQL command sequence, which causes a segmentation fault.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-3119?
CVE-2021-3119 has been classified as a medium severity vulnerability due to its potential for remote denial of service attacks.
How do I fix CVE-2021-3119?
To fix CVE-2021-3119, upgrade to SQLCipher version 4.4.3 or later.
What type of vulnerability is CVE-2021-3119?
CVE-2021-3119 is a NULL pointer dereferencing vulnerability that can lead to denial of service.
Which versions of SQLCipher are affected by CVE-2021-3119?
CVE-2021-3119 affects all versions of SQLCipher 4.x prior to 4.4.3.
What can exploit CVE-2021-3119?
An attacker can exploit CVE-2021-3119 through SQL injection to execute crafted SQL commands.