CVE-2018-20346
Last modified
CVE-2018-20346 is a vulnerability of currently unknown severity. SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries that occur after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases), aka Magellan.. EPSS estimates a 9.68% chance of exploitation in the next 30 days.
Description
SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries that occur after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases), aka Magellan.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sqlite | Sqlite | < 3.25.3 |
| Chrome | < 71.0.3578.80 | |
| Redhat | Linux | 6.0 |
| Debian | Debian Linux | 8.0 |
| Opensuse | Leap | 15.0 |
| Opensuse | Leap | 42.3 |
References
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00040.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00070.htmlMailing List, Third Party Advisory
- http://www.securityfocus.com/bid/106323Third Party Advisory, VDB Entry
- https://access.redhat.com/articles/3758321Third Party Advisory
- https://blade.tencent.com/magellan/index_en.htmlThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1659379Issue Tracking, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1659677Issue Tracking, Third Party Advisory
- https://crbug.com/900910Permissions Required, Third Party Advisory
- https://github.com/zhuowei/worthdoingbadly.com/blob/master/_posts/2018-12-14-sqlitebug.htmlExploit, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/12/msg00012.htmlMailing List, Third Party Advisory
- https://news.ycombinator.com/item?id=18685296Third Party Advisory
- https://security.gentoo.org/glsa/201904-21Third Party Advisory
- https://sqlite.org/src/info/940f2adc8541a838Patch, Third Party Advisory
- https://sqlite.org/src/info/d44318f59044162ePatch, Third Party Advisory
- https://worthdoingbadly.com/sqlitebug/Exploit, Third Party Advisory
- https://www.freebsd.org/security/advisories/FreeBSD-EN-19:03.sqlite.ascThird Party Advisory
- https://www.sqlite.org/releaselog/3_25_3.htmlRelease Notes, Vendor Advisory
- https://www.synology.com/security/advisory/Synology_SA_18_61Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00040.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00070.htmlMailing List, Third Party Advisory
- http://www.securityfocus.com/bid/106323Third Party Advisory, VDB Entry
- https://access.redhat.com/articles/3758321Third Party Advisory
- https://blade.tencent.com/magellan/index_en.htmlThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1659379Issue Tracking, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1659677Issue Tracking, Third Party Advisory
- https://crbug.com/900910Permissions Required, Third Party Advisory
- https://github.com/zhuowei/worthdoingbadly.com/blob/master/_posts/2018-12-14-sqlitebug.htmlExploit, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/12/msg00012.htmlMailing List, Third Party Advisory
- https://news.ycombinator.com/item?id=18685296Third Party Advisory
- https://security.gentoo.org/glsa/201904-21Third Party Advisory
- https://sqlite.org/src/info/940f2adc8541a838Patch, Third Party Advisory
- https://sqlite.org/src/info/d44318f59044162ePatch, Third Party Advisory
- https://worthdoingbadly.com/sqlitebug/Exploit, Third Party Advisory
- https://www.freebsd.org/security/advisories/FreeBSD-EN-19:03.sqlite.ascThird Party Advisory
- https://www.sqlite.org/releaselog/3_25_3.htmlRelease Notes, Vendor Advisory
- https://www.synology.com/security/advisory/Synology_SA_18_61Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-20346?
How severe is CVE-2018-20346?
How do I fix CVE-2018-20346?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-2034Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2018-20340Yubico libu2f-host 1.1.6 contains unchecked buffers in devs.…
- CVE-2018-20341WINMAGIC SecureDoc Disk Encryption software before 8.3 has a…
- CVE-2018-20342The Floureon IP Camera SP012 provides a root terminal on a U…
- CVE-2018-20343Multiple buffer overflow vulnerabilities have been found in …7.8
- CVE-2018-20345Incorrect access control in StackStorm API (st2api) in Stack…
- CVE-2018-20347Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2018-20348libpff_item_tree_create_node in libpff_item_tree.c in libpff…
- CVE-2018-20349The igraph_i_strdiff function in igraph_trie.c in igraph thr…
- CVE-2018-2035Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2018-20351The Markdown component in Evernote (Chinese) before 8.3.2 on…
- CVE-2018-20352Use-after-free vulnerability in the mg_cgi_ev_handler functi…
Are you affected by CVE-2018-20346?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
