Lucene search

K
f5F5F5:K000130512
HistoryJan 06, 2023 - 12:00 a.m.

K000130512 : SQLite vulnerability CVE-2022-35737

2023-01-0600:00:00
my.f5.com
10
sqlite
vulnerability
cve-2022-35737
array-bounds overflow
c api
denial of service
control plane.

AI Score

7.5

Confidence

High

EPSS

0.003

Percentile

65.5%

Security Advisory Description

SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API. (CVE-2022-35737)

Impact

An authenticated remote attacker can exploit this vulnerability by sending a specially crafted large input to the application and perform a denial of service (DoS) attack to the sqlite component. There is no data plane exposure; this is a control plane issue only.