CVE-2018-20506
Last modified
CVE-2018-20506 is a vulnerability of currently unknown severity. SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases). This is a different vulnerability than CVE-2018-20346.. EPSS estimates a 7.53% chance of exploitation in the next 30 days.
Description
SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases). This is a different vulnerability than CVE-2018-20346.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sqlite | Sqlite | < 3.25.3 |
| Apple | Iphone Os | < 12.1.3 |
| Apple | Mac Os X | < 10.14.3 |
| Apple | Tvos | < 12.1.2 |
| Apple | Watchos | < 5.1.3 |
| Apple | Icloud | <= 7.10 |
| Apple | Itunes | <= 12.9.3 |
| Opensuse | Leap | 42.3 |
References
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00070.htmlMailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2019/Jan/62Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2019/Jan/64Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2019/Jan/66Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2019/Jan/67Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2019/Jan/68Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2019/Jan/69Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/106698Third Party Advisory, VDB Entry
- https://seclists.org/bugtraq/2019/Jan/28Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Jan/29Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Jan/31Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Jan/32Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Jan/33Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Jan/39Mailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20190502-0004/Third Party Advisory
- https://sqlite.org/src/info/940f2adc8541a838Vendor Advisory
- https://support.apple.com/kb/HT209443Third Party Advisory
- https://support.apple.com/kb/HT209446Third Party Advisory
- https://support.apple.com/kb/HT209447Third Party Advisory
- https://support.apple.com/kb/HT209448Third Party Advisory
- https://support.apple.com/kb/HT209450Third Party Advisory
- https://support.apple.com/kb/HT209451Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00070.htmlMailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2019/Jan/62Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2019/Jan/64Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2019/Jan/66Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2019/Jan/67Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2019/Jan/68Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2019/Jan/69Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/106698Third Party Advisory, VDB Entry
- https://seclists.org/bugtraq/2019/Jan/28Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Jan/29Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Jan/31Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Jan/32Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Jan/33Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Jan/39Mailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20190502-0004/Third Party Advisory
- https://sqlite.org/src/info/940f2adc8541a838Vendor Advisory
- https://support.apple.com/kb/HT209443Third Party Advisory
- https://support.apple.com/kb/HT209446Third Party Advisory
- https://support.apple.com/kb/HT209447Third Party Advisory
- https://support.apple.com/kb/HT209448Third Party Advisory
- https://support.apple.com/kb/HT209450Third Party Advisory
- https://support.apple.com/kb/HT209451Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-20506?
How severe is CVE-2018-20506?
How do I fix CVE-2018-20506?
Are you affected by CVE-2018-20506?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
