Description
Zetetic SQLCipher 4.x before 4.4.1 has a use-after-free, related to sqlcipher_codec_pragma and sqlite3Strlen30 in sqlite3.c. A remote denial of service attack can be performed. For example, a SQL injection can be used to execute the crafted SQL command sequence. After that, some unexpected RAM data is read.
References (3)
Core 3
Core References
Third Party Advisory x_refsource_misc
https://www.telekom.com/en/corporate-responsibility/data-protection-data-security/security/details/advisories-504842
Third Party Advisory x_refsource_confirm
https://github.com/sqlcipher/sqlcipher/compare/v4.4.0...v4.4.1
Third Party Advisory x_refsource_misc
https://www.telekom.com/resource/blob/612796/9f221708832a465f03585a45d7f59b45/dl-201112-denial-of-serviceen-data.pdf
Scores
CVSS v3
7.5
EPSS
0.0157
EPSS Percentile
72.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-416
Status
published
Products (1)
zetetic/sqlcipher
4.0 - 4.4.1
Published
Nov 26, 2020
Tracked Since
Feb 18, 2026