REDHAT-BUG-1789364: SQL Injection
multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsing, as demonstrated by errors from sqlite3WindowRewrite() calls. NOTE: this vulnerability exists because of an incomplete fix for CVE-2019-19880.
Upstream commit:
https://github.com/sqlite/sqlite/commit/8428b3b437569338a9d1e10c4cd8154acbe33089
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1789364?
The severity of REDHAT-BUG-1789364 is classified as a medium risk due to the potential for mishandled errors during parsing.
How can I fix REDHAT-BUG-1789364?
To fix REDHAT-BUG-1789364, upgrade to the latest version of SQLite that addresses this vulnerability.
What causes the vulnerabilities in REDHAT-BUG-1789364?
REDHAT-BUG-1789364 is caused by an incomplete fix for a prior vulnerability in SQLite, leading to improper error handling.
Which versions of SQLite are affected by REDHAT-BUG-1789364?
SQLite 3.30.1 is specifically mentioned as having the vulnerability associated with REDHAT-BUG-1789364.
Is REDHAT-BUG-1789364 related to any other vulnerabilities?
Yes, REDHAT-BUG-1789364 is related to CVE-2019-19880, as it stems from an incomplete fix for that vulnerability.