Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:25222
HistoryMay 10, 2020 - 11:21 p.m.

Arbitrary Code Execution

2020-05-1023:21:03
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
19

EPSS

0.009

Percentile

83.2%

sqlite is vulnerable to arbitrary code execution. The vulnerability exists as the getNodeSize function in ext/rtree/rtree.c in SQLite through 3.19.3, as used in GDAL and other products, mishandles undersized RTree blobs in a crafted database, leading to a heap-based buffer over-read or possibly unspecified other impact.