Lucene search

K
ubuntucveUbuntu.comUB:CVE-2021-36690
HistoryAug 24, 2021 - 12:00 a.m.

CVE-2021-36690

2021-08-2400:00:00
ubuntu.com
ubuntu.com
27

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.004 Low

EPSS

Percentile

74.7%

DISPUTED A segmentation fault can occur in the sqlite3.exe
command-line component of SQLite 3.36.0 via the idxGetTableInfo function
when there is a crafted SQL query. NOTE: the vendor disputes the relevance
of this report because a sqlite3.exe user already has full privileges
(e.g., is intentionally allowed to execute commands). This report does NOT
imply any problem in the SQLite library.

Notes

Author Note
sbeattie issue only affects the command line tool of sqlite expert extension was introduced in sqlite3 after xenial (16.04) PoC in issue report
OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchsqlite3< 3.22.0-1ubuntu0.5UNKNOWN
ubuntu20.04noarchsqlite3< 3.31.1-4ubuntu0.3UNKNOWN
ubuntu21.10noarchsqlite3< 3.35.5-1ubuntu0.1UNKNOWN

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.004 Low

EPSS

Percentile

74.7%