Vulnerability Description
A Memory Leak vulnerability exists in SQLite Project SQLite3 3.35.1 and 3.37.0 via maliciously crafted SQL Queries (made via editing the Database File), it is possible to query a record, and leak subsequent bytes of memory that extend beyond the record, which could let a malicious user obtain sensitive information. NOTE: The developer disputes this as a vulnerability stating that If you give SQLite a corrupted database file and submit a query against the database, it might read parts of the database that you did not intend or expect.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sqlite | Sqlite | 3.35.1 |
| Netapp | Ontap Select Deploy Administration Utility | - |
Related Weaknesses (CWE)
References
- https://github.com/guyinatuxedo/sqlite3_record_leakingExploitThird Party Advisory
- https://security.netapp.com/advisory/ntap-20220303-0001/Third Party Advisory
- https://sqlite.org/forum/forumpost/056d557c2f8c452ed5Vendor Advisory
- https://sqlite.org/forum/forumpost/53de8864ba114bf6Vendor Advisory
- https://www.sqlite.org/cves.html#status_of_recent_sqlite_cvesVendor Advisory
- https://github.com/guyinatuxedo/sqlite3_record_leakingExploitThird Party Advisory
- https://security.netapp.com/advisory/ntap-20220303-0001/Third Party Advisory
- https://sqlite.org/forum/forumpost/056d557c2f8c452ed5Vendor Advisory
- https://sqlite.org/forum/forumpost/53de8864ba114bf6Vendor Advisory
- https://www.sqlite.org/cves.html#status_of_recent_sqlite_cvesVendor Advisory
FAQ
What is CVE-2021-45346?
CVE-2021-45346 is a vulnerability with a CVSS score of 4.3 (MEDIUM). A Memory Leak vulnerability exists in SQLite Project SQLite3 3.35.1 and 3.37.0 via maliciously crafted SQL Queries (made via editing the Database File), it is possible to query a record, and leak subs...
How severe is CVE-2021-45346?
CVE-2021-45346 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-45346?
Check the references section above for vendor advisories and patch information. Affected products include: Sqlite Sqlite, Netapp Ontap Select Deploy Administration Utility.