Lucene search

K
sqliteSQLite ORGSQLT:CVE-2024-0232
HistoryJan 01, 2024 - 12:00 a.m.

SQLite report about CVE-2024-0232

2024-01-0100:00:00
SQLite ORG
3
sqlite
cve-2024-0232
sql injection
application crash
denial of service
bug report

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

7.7 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

26.7%

An attacker that can inject arbitrary SQL statements into an application might be able to provoke a use-after-free bug in SQLite’s JSON parser that can (in theory) lead to an application crash and denial of service. See forum thread b25edc1d4662 for the bug report.

CPENameOperatorVersion
sqlitelt3.43.2
sqlitelt2023
sqlitelt10
sqlitelt10

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

7.7 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

26.7%