CVE-2018-20346
Last modified
CVE-2018-20346 is a vulnerability of currently unknown severity. SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries that occur after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases), aka Magellan.. EPSS estimates a 9.68% chance of exploitation in the next 30 days.
Description
SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries that occur after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases), aka Magellan.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sqlite | Sqlite | < 3.25.3 |
| Chrome | < 71.0.3578.80 | |
| Redhat | Linux | 6.0 |
| Debian | Debian Linux | 8.0 |
| Opensuse | Leap | 15.0 |
| Opensuse | Leap | 42.3 |
References
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00040.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00070.htmlMailing List, Third Party Advisory
- http://www.securityfocus.com/bid/106323Third Party Advisory, VDB Entry
- https://access.redhat.com/articles/3758321Third Party Advisory
- https://blade.tencent.com/magellan/index_en.htmlThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1659379Issue Tracking, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1659677Issue Tracking, Third Party Advisory
- https://crbug.com/900910Permissions Required, Third Party Advisory
- https://github.com/zhuowei/worthdoingbadly.com/blob/master/_posts/2018-12-14-sqlitebug.htmlExploit, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/12/msg00012.htmlMailing List, Third Party Advisory
- https://news.ycombinator.com/item?id=18685296Third Party Advisory
- https://security.gentoo.org/glsa/201904-21Third Party Advisory
- https://sqlite.org/src/info/940f2adc8541a838Patch, Third Party Advisory
- https://sqlite.org/src/info/d44318f59044162ePatch, Third Party Advisory
- https://worthdoingbadly.com/sqlitebug/Exploit, Third Party Advisory
- https://www.freebsd.org/security/advisories/FreeBSD-EN-19:03.sqlite.ascThird Party Advisory
- https://www.sqlite.org/releaselog/3_25_3.htmlRelease Notes, Vendor Advisory
- https://www.synology.com/security/advisory/Synology_SA_18_61Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00040.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00070.htmlMailing List, Third Party Advisory
- http://www.securityfocus.com/bid/106323Third Party Advisory, VDB Entry
- https://access.redhat.com/articles/3758321Third Party Advisory
- https://blade.tencent.com/magellan/index_en.htmlThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1659379Issue Tracking, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1659677Issue Tracking, Third Party Advisory
- https://crbug.com/900910Permissions Required, Third Party Advisory
- https://github.com/zhuowei/worthdoingbadly.com/blob/master/_posts/2018-12-14-sqlitebug.htmlExploit, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/12/msg00012.htmlMailing List, Third Party Advisory
- https://news.ycombinator.com/item?id=18685296Third Party Advisory
- https://security.gentoo.org/glsa/201904-21Third Party Advisory
- https://sqlite.org/src/info/940f2adc8541a838Patch, Third Party Advisory
- https://sqlite.org/src/info/d44318f59044162ePatch, Third Party Advisory
- https://worthdoingbadly.com/sqlitebug/Exploit, Third Party Advisory
- https://www.freebsd.org/security/advisories/FreeBSD-EN-19:03.sqlite.ascThird Party Advisory
- https://www.sqlite.org/releaselog/3_25_3.htmlRelease Notes, Vendor Advisory
- https://www.synology.com/security/advisory/Synology_SA_18_61Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-20346?
How severe is CVE-2018-20346?
How do I fix CVE-2018-20346?
Are you affected by CVE-2018-20346?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
