F5-K000141088: SQL Injection
The getNodeSize function in ext/rtree/rtree.c in SQLite through 3.19.3, as used in GDAL and other products, mishandles undersized RTree blobs in a crafted database, leading to a heap-based buffer over-read or possibly unspecified other impact.
Affected Software
Event History
Frequently Asked Questions
What is the severity of F5-K000141088?
The severity of F5-K000141088 is classified as high due to the potential for heap-based buffer over-read.
How do I fix F5-K000141088?
To fix F5-K000141088, upgrade to a version of the software that is not affected by the vulnerability.
Which versions of F5 Traffix SDC are affected by F5-K000141088?
F5-K000141088 specifically affects F5 Traffix SDC version 5.1.0.
What products utilize the vulnerable getNodeSize function as per F5-K000141088?
The vulnerable getNodeSize function is utilized by SQLite versions through 3.19.3, which is found in GDAL and other products.
What is the potential impact of F5-K000141088?
The potential impact of F5-K000141088 includes a heap-based buffer over-read and possibly other unspecified effects.