CVE-2019-16168

MEDIUM

SQLite <3.29.0 - Info Disclosure

Title source: llm

Description

In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validation of a sqlite_stat1 sz field, aka a "severe division by zero in the query planner."

Scores

CVSS v3 6.5
EPSS 0.0084
EPSS Percentile 74.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Classification

CWE
CWE-369
Status published

Affected Products (27)

sqlite/sqlite < 3.29.0
netapp/active_iq_unified_manager
netapp/active_iq_unified_manager
netapp/e-series_santricity_os_controller < 11.60.3
netapp/oncommand_insight
netapp/oncommand_workflow_automation
netapp/ontap_select_deploy_administration_utility
netapp/santricity_unified_manager
netapp/steelstore_cloud_integrated_storage
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
fedoraproject/fedora
... and 12 more

Timeline

Published Sep 09, 2019
Tracked Since Feb 18, 2026