CVE-2021-20227

MEDIUM

SQLite 3.33.0-3.34.0 - Use-After-Free in SELECT Query Processing

Title source: llm
STIX 2.1

Description

A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on the SQLite database to cause a denial of service or possible code execution by triggering a use-after-free. The highest threat from this vulnerability is to system availability.

References (8)

Core 8
Core References
Third Party Advisory vendor-advisory
https://security.gentoo.org/glsa/202103-04
Third Party Advisory vendor-advisory
https://security.gentoo.org/glsa/202210-40
Issue Tracking, Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1924886
Release Notes, Vendor Advisory
https://www.sqlite.org/releaselog/3_34_1.html

Scores

CVSS v3 5.5
EPSS 0.0021
EPSS Percentile 43.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-416
Status published
Products (8)
oracle/communications_network_charging_and_control 6.0.1
oracle/communications_network_charging_and_control 12.0.1.0 - 12.0.4.0.0
oracle/enterprise_manager_for_oracle_database 13.4.0.0
oracle/jd_edwards_enterpriseone_tools < 9.2.6.0
oracle/mysql_workbench < 8.0.26
oracle/outside_in_technology 8.5.5
oracle/zfs_storage_appliance_kit 8.8
sqlite/sqlite 3.33.0 - 3.34.1
Published Mar 23, 2021
Tracked Since Feb 18, 2026