CVE-2021-20227
MEDIUMSQLite 3.33.0-3.34.0 - Use-After-Free in SELECT Query Processing
Title source: llmDescription
A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on the SQLite database to cause a denial of service or possible code execution by triggering a use-after-free. The highest threat from this vulnerability is to system availability.
References (8)
Core 8
Core References
Third Party Advisory vendor-advisory
https://security.gentoo.org/glsa/202103-04
Third Party Advisory vendor-advisory
https://security.gentoo.org/glsa/202210-40
Issue Tracking, Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1924886
Third Party Advisory
https://security.netapp.com/advisory/ntap-20210423-0010/
Patch, Third Party Advisory
https://www.oracle.com//security-alerts/cpujul2021.html
Patch, Third Party Advisory
https://www.oracle.com/security-alerts/cpuApr2021.html
Patch, Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2021.html
Release Notes, Vendor Advisory
https://www.sqlite.org/releaselog/3_34_1.html
Scores
CVSS v3
5.5
EPSS
0.0021
EPSS Percentile
43.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-416
Status
published
Products (8)
oracle/communications_network_charging_and_control
6.0.1
oracle/communications_network_charging_and_control
12.0.1.0 - 12.0.4.0.0
oracle/enterprise_manager_for_oracle_database
13.4.0.0
oracle/jd_edwards_enterpriseone_tools
< 9.2.6.0
oracle/mysql_workbench
< 8.0.26
oracle/outside_in_technology
8.5.5
oracle/zfs_storage_appliance_kit
8.8
sqlite/sqlite
3.33.0 - 3.34.1
Published
Mar 23, 2021
Tracked Since
Feb 18, 2026