CVE-2025-70873: SQL Injection
An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.9.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.9.83 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.11.60 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.39.2-5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.14.40 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.44.0-3
Event History
Frequently Asked Questions
What is the severity of CVE-2025-70873?
CVE-2025-70873 has been classified as a moderate severity vulnerability due to its potential for information disclosure.
How do I fix CVE-2025-70873?
To fix CVE-2025-70873, upgrade SQLite to version 3.51.2 or later.
What versions of SQLite are affected by CVE-2025-70873?
CVE-2025-70873 affects SQLite versions 3.51.1 and earlier.
What type of vulnerability is CVE-2025-70873?
CVE-2025-70873 is an information disclosure vulnerability.
What can attackers achieve by exploiting CVE-2025-70873?
By exploiting CVE-2025-70873, attackers can potentially obtain sensitive heap memory data by supplying a crafted ZIP file.