First published: Tue Sep 17 2024(Updated: )
The getNodeSize function in ext/rtree/rtree.c in SQLite through 3.19.3, as used in GDAL and other products, mishandles undersized RTree blobs in a crafted database, leading to a heap-based buffer over-read or possibly unspecified other impact.
Affected Software | Affected Version | How to fix |
---|---|---|
F5 Traffix Systems Signaling Delivery Controller | =5.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of F5-K000141088 is classified as high due to the potential for heap-based buffer over-read.
To fix F5-K000141088, upgrade to a version of the software that is not affected by the vulnerability.
F5-K000141088 specifically affects F5 Traffix SDC version 5.1.0.
The vulnerable getNodeSize function is utilized by SQLite versions through 3.19.3, which is found in GDAL and other products.
The potential impact of F5-K000141088 includes a heap-based buffer over-read and possibly other unspecified effects.