MEDIUM · 5.5

CVE-2021-20227

A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on the SQLite database to cause a denial of service o...

Vulnerability Description

A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on the SQLite database to cause a denial of service or possible code execution by triggering a use-after-free. The highest threat from this vulnerability is to system availability.

CVSS Score

5.5

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
SqliteSqlite>= 3.33.0, < 3.34.1
OracleCommunications Network Charging And Control>= 12.0.1.0, <= 12.0.4.0.0
OracleEnterprise Manager For Oracle Database13.4.0.0
OracleJd Edwards Enterpriseone Tools< 9.2.6.0
OracleMysql Workbench<= 8.0.26
OracleOutside In Technology8.5.5
OracleZfs Storage Appliance Kit8.8

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-20227?

CVE-2021-20227 is a vulnerability with a CVSS score of 5.5 (MEDIUM). A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on the SQLite database to cause a denial of service o...

How severe is CVE-2021-20227?

CVE-2021-20227 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-20227?

Check the references section above for vendor advisories and patch information. Affected products include: Sqlite Sqlite, Oracle Communications Network Charging And Control, Oracle Enterprise Manager For Oracle Database, Oracle Jd Edwards Enterpriseone Tools, Oracle Mysql Workbench.