CVE-2018-20346

MEDIUM

Description

SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries that occur after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases), aka Magellan.

References

http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00040.html

http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00070.html

http://www.securityfocus.com/bid/106323

https://access.redhat.com/articles/3758321

https://blade.tencent.com/magellan/index_en.html

https://bugzilla.redhat.com/show_bug.cgi?id=1659379

https://bugzilla.redhat.com/show_bug.cgi?id=1659677

https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html

https://chromium.googlesource.com/chromium/src/+/c368e30ae55600a1c3c9cb1710a54f9c55de786e

https://crbug.com/900910

https://github.com/zhuowei/worthdoingbadly.com/blob/master/_posts/2018-12-14-sqlitebug.html

https://lists.debian.org/debian-lts-announce/2018/12/msg00012.html

https://lists.fedoraproject.org/archives/list/[email protected]/message/PU4NZ6DDU4BEM3ACM3FM6GLEPX56ZQXK/

https://news.ycombinator.com/item?id=18685296

https://security.gentoo.org/glsa/201904-21

https://sqlite.org/src/info/940f2adc8541a838

https://sqlite.org/src/info/d44318f59044162e

https://usn.ubuntu.com/4019-1/

https://usn.ubuntu.com/4019-2/

https://worthdoingbadly.com/sqlitebug/

https://www.freebsd.org/security/advisories/FreeBSD-EN-19:03.sqlite.asc

https://www.mail-archive.com/[email protected]/msg113218.html

https://www.sqlite.org/releaselog/3_25_3.html

https://www.synology.com/security/advisory/Synology_SA_18_61

Details

Source: MITRE

Published: 2018-12-21

Updated: 2019-06-19

Type: CWE-190

Risk Information

CVSS v2.0

Base Score: 6.8

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 8.6

Severity: MEDIUM

CVSS v3.0

Base Score: 8.1

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 2.2

Severity: HIGH