Lucene search

K
f5F5F5:K37236006
HistoryJun 07, 2016 - 12:00 a.m.

K37236006 : SQLite vulnerabilities CVE-2015-3414 and CVE-2015-3415

2016-06-0700:00:00
my.f5.com
16

8.7 High

AI Score

Confidence

High

0.008 Low

EPSS

Percentile

82.0%

Security Advisory Description

SQLite before 3.8.9 does not properly implement the dequoting of collation-sequence names, which allows context-dependent attackers to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other impact via a crafted COLLATE clause, as demonstrated by COLLATE"“”“”“”" at the end of a SELECT statement.

The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly implement comparison operators, which allows context-dependent attackers to cause a denial of service (invalid free operation) or possibly have unspecified other impact via a crafted CHECK clause, as demonstrated by CHECK(0&O>O) in a CREATE TABLE statement.
Impact
Attackers may be able to cause a denial-of service (DoS) attack. For potential impact regarding each vulnerability, refer to the CVE descriptions.