Vulnerability Description
SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases). This is a different vulnerability than CVE-2018-20346.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sqlite | Sqlite | < 3.25.3 |
| Apple | Iphone Os | < 12.1.3 |
| Apple | Mac Os X | < 10.14.3 |
| Apple | Tvos | < 12.1.2 |
| Apple | Watchos | < 5.1.3 |
| Apple | Icloud | <= 7.10 |
| Apple | Itunes | <= 12.9.3 |
| Microsoft | Windows | - |
| Opensuse | Leap | 42.3 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00070.htmlMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2019/Jan/62Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2019/Jan/64Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2019/Jan/66Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2019/Jan/67Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2019/Jan/68Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2019/Jan/69Mailing ListThird Party Advisory
- http://www.securityfocus.com/bid/106698Third Party AdvisoryVDB Entry
- https://kc.mcafee.com/corporate/index?page=content&id=SB10365
- https://lists.debian.org/debian-lts-announce/2020/08/msg00037.html
- https://seclists.org/bugtraq/2019/Jan/28Mailing ListThird Party Advisory
- https://seclists.org/bugtraq/2019/Jan/29Mailing ListThird Party Advisory
- https://seclists.org/bugtraq/2019/Jan/31Mailing ListThird Party Advisory
- https://seclists.org/bugtraq/2019/Jan/32Mailing ListThird Party Advisory
- https://seclists.org/bugtraq/2019/Jan/33Mailing ListThird Party Advisory
FAQ
What is CVE-2018-20506?
CVE-2018-20506 is a vulnerability with a CVSS score of 8.1 (HIGH). SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FT...
How severe is CVE-2018-20506?
CVE-2018-20506 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-20506?
Check the references section above for vendor advisories and patch information. Affected products include: Sqlite Sqlite, Apple Iphone Os, Apple Mac Os X, Apple Tvos, Apple Watchos.