CVE-2018-20506

MEDIUM

Description

SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases). This is a different vulnerability than CVE-2018-20346.

References

http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00070.html

http://seclists.org/fulldisclosure/2019/Jan/62

http://seclists.org/fulldisclosure/2019/Jan/64

http://seclists.org/fulldisclosure/2019/Jan/66

http://seclists.org/fulldisclosure/2019/Jan/67

http://seclists.org/fulldisclosure/2019/Jan/68

http://seclists.org/fulldisclosure/2019/Jan/69

http://www.securityfocus.com/bid/106698

https://lists.debian.org/debian-lts-announce/2020/08/msg00037.html

https://seclists.org/bugtraq/2019/Jan/28

https://seclists.org/bugtraq/2019/Jan/29

https://seclists.org/bugtraq/2019/Jan/31

https://seclists.org/bugtraq/2019/Jan/32

https://seclists.org/bugtraq/2019/Jan/33

https://seclists.org/bugtraq/2019/Jan/39

https://security.netapp.com/advisory/ntap-20190502-0004/

https://sqlite.org/src/info/940f2adc8541a838

https://support.apple.com/kb/HT209443

https://support.apple.com/kb/HT209446

https://support.apple.com/kb/HT209447

https://support.apple.com/kb/HT209448

https://support.apple.com/kb/HT209450

https://support.apple.com/kb/HT209451

https://usn.ubuntu.com/4019-1/

https://usn.ubuntu.com/4019-2/

https://www.oracle.com/security-alerts/cpuapr2020.html

Details

Source: MITRE

Published: 2019-04-03

Updated: 2020-08-23

Type: CWE-190

Risk Information

CVSS v2.0

Base Score: 6.8

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 8.6

Severity: MEDIUM

CVSS v3.0

Base Score: 8.1

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 2.2

Severity: HIGH