First published: Wed Aug 03 2022(Updated: )
MITRE: CVE-2022-35737 SQLite allows an array-bounds overflow
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SQLite SQLite | >=1.0.12<3.39.2 | |
NetApp ONTAP Select Deploy administration utility | ||
Microsoft Windows 10 | =22H2 | |
Microsoft Windows 10 | =22H2 | |
Microsoft Windows Server 2022 | ||
Microsoft Windows 10 | =21H2 | |
Microsoft Windows Server 2019 | ||
Microsoft Windows 10 | =21H2 | |
Microsoft Windows Server 2019 | ||
Microsoft Windows 10 | =22H2 | |
Microsoft Windows 10 | =1809 | |
Microsoft Windows 10 | =1809 | |
Microsoft Windows 10 | =21H2 | |
Microsoft Windows Server 2022 | ||
Microsoft Windows 10 | =1809 | |
Microsoft CBL Mariner 2.0 ARM | ||
Microsoft CBL Mariner 1.0 ARM | ||
Microsoft CBL Mariner 2.0 x64 | ||
Microsoft CBL Mariner 1.0 x64 | ||
Splunk Universal Forwarder | >=8.2.0<8.2.12 | |
Splunk Universal Forwarder | >=9.0.0<9.0.6 | |
Splunk Universal Forwarder | =9.1.0 | |
rust/libsqlite3-sys | <0.25.1 | 0.25.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-35737.
The severity of CVE-2022-35737 is high with a severity value of 7.5.
SQLite versions 1.0.12 through 3.39.x before 3.39.2 and NetApp ONTAP Select Deploy administration utility are affected by CVE-2022-35737.
CVE-2022-35737 is a vulnerability in SQLite that sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.
You can find more information about CVE-2022-35737 at the following references: [https://blog.trailofbits.com/2022/10/25/sqlite-vulnerability-july-2022-library-api/](https://blog.trailofbits.com/2022/10/25/sqlite-vulnerability-july-2022-library-api/), [https://kb.cert.org/vuls/id/720344](https://kb.cert.org/vuls/id/720344), [https://security.gentoo.org/glsa/202210-40](https://security.gentoo.org/glsa/202210-40)