CVE-2018-20505

HIGH

SQLite < 3.25.2 - Denial of Service via Malformed PRIMARY KEY

Title source: llm
STIX 2.1

Description

SQLite 3.25.2, when queries are run on a table with a malformed PRIMARY KEY, allows remote attackers to cause a denial of service (application crash) by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases).

References (22)

Core 22
Core References
Mailing List, Third Party Advisory x_refsource_misc
http://seclists.org/fulldisclosure/2019/Jan/62
Mailing List, Third Party Advisory x_refsource_misc
http://seclists.org/fulldisclosure/2019/Jan/64
Mailing List, Third Party Advisory x_refsource_misc
http://seclists.org/fulldisclosure/2019/Jan/66
Mailing List, Third Party Advisory x_refsource_misc
http://seclists.org/fulldisclosure/2019/Jan/67
Mailing List, Third Party Advisory x_refsource_misc
http://seclists.org/fulldisclosure/2019/Jan/68
Mailing List, Third Party Advisory x_refsource_misc
http://seclists.org/fulldisclosure/2019/Jan/69
Third Party Advisory, VDB Entry x_refsource_misc
http://www.securityfocus.com/bid/106698
Mailing List, Third Party Advisory x_refsource_misc
https://seclists.org/bugtraq/2019/Jan/28
Mailing List, Third Party Advisory x_refsource_misc
https://seclists.org/bugtraq/2019/Jan/29
Mailing List, Third Party Advisory x_refsource_misc
https://seclists.org/bugtraq/2019/Jan/31
Mailing List, Third Party Advisory x_refsource_misc
https://seclists.org/bugtraq/2019/Jan/32
Mailing List, Third Party Advisory x_refsource_misc
https://seclists.org/bugtraq/2019/Jan/33
Mailing List, Third Party Advisory x_refsource_misc
https://seclists.org/bugtraq/2019/Jan/39
Vendor Advisory x_refsource_misc
https://support.apple.com/kb/HT209443
Vendor Advisory x_refsource_misc
https://support.apple.com/kb/HT209446
Vendor Advisory x_refsource_misc
https://support.apple.com/kb/HT209447
Vendor Advisory x_refsource_misc
https://support.apple.com/kb/HT209448
Vendor Advisory x_refsource_misc
https://support.apple.com/kb/HT209450
Vendor Advisory x_refsource_misc
https://support.apple.com/kb/HT209451
Exploit, Vendor Advisory x_refsource_misc
https://sqlite.org/src/info/1a84668dcfdebaf12415d
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20190502-0004/
Vendor Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/4019-1/

Scores

CVSS v3 7.5
EPSS 0.0695
EPSS Percentile 93.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-89
Status published
Products (6)
apple/icloud < 7.10
apple/iphone_os < 12.1.3
apple/itunes < 12.9.3
apple/mac_os_x < 10.14.2
apple/watchos < 5.1.3
sqlite/sqlite < 3.25.2
Published Apr 03, 2019
Tracked Since Feb 18, 2026