Vulnerability Description
pragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sqlite | Sqlite | <= 3.30.1 |
| Siemens | Sinec Infrastructure Network Services | < 1.0.1.1 |
| Tenable | Tenable.Sc | < 5.19.0 |
| Oracle | Mysql Workbench | <= 8.0.19 |
| Netapp | Cloud Backup | - |
| Netapp | Ontap Select Deploy Administration Utility | - |
Related Weaknesses (CWE)
References
- https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdfPatchThird Party Advisory
- https://github.com/sqlite/sqlite/commit/926f796e8feec15f3836aa0a060ed906f8ae04d3Third Party Advisory
- https://github.com/sqlite/sqlite/commit/ebd70eedd5d6e6a890a670b5ee874a5eae86b4ddPatchThird Party Advisory
- https://security.netapp.com/advisory/ntap-20191223-0001/Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2020.htmlPatchThird Party Advisory
- https://www.sqlite.org/Vendor Advisory
- https://www.tenable.com/security/tns-2021-14Third Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdfPatchThird Party Advisory
- https://github.com/sqlite/sqlite/commit/926f796e8feec15f3836aa0a060ed906f8ae04d3Third Party Advisory
- https://github.com/sqlite/sqlite/commit/ebd70eedd5d6e6a890a670b5ee874a5eae86b4ddPatchThird Party Advisory
- https://security.netapp.com/advisory/ntap-20191223-0001/Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2020.htmlPatchThird Party Advisory
- https://www.sqlite.org/Vendor Advisory
- https://www.tenable.com/security/tns-2021-14Third Party Advisory
FAQ
What is CVE-2019-19646?
CVE-2019-19646 is a vulnerability with a CVSS score of 9.8 (CRITICAL). pragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns.
How severe is CVE-2019-19646?
CVE-2019-19646 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-19646?
Check the references section above for vendor advisories and patch information. Affected products include: Sqlite Sqlite, Siemens Sinec Infrastructure Network Services, Tenable Tenable.Sc, Oracle Mysql Workbench, Netapp Cloud Backup.