Vulnerability Description
SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sqlite | Sqlite | >= 1.0.12, < 3.39.2 |
| Netapp | Ontap Select Deploy Administration Utility | - |
| Splunk | Universal Forwarder | >= 8.2.0, < 8.2.12 |
Related Weaknesses (CWE)
References
- https://blog.trailofbits.com/2022/10/25/sqlite-vulnerability-july-2022-library-aExploitThird Party Advisory
- https://kb.cert.org/vuls/id/720344Broken LinkThird Party AdvisoryUS Government Resource
- https://security.gentoo.org/glsa/202210-40Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220915-0009/Third Party Advisory
- https://sqlite.org/releaselog/3_39_2.htmlRelease NotesVendor Advisory
- https://www.sqlite.org/cves.htmlVendor Advisory
- https://blog.trailofbits.com/2022/10/25/sqlite-vulnerability-july-2022-library-aExploitThird Party Advisory
- https://kb.cert.org/vuls/id/720344Broken LinkThird Party AdvisoryUS Government Resource
- https://security.gentoo.org/glsa/202210-40Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220915-0009/Third Party Advisory
- https://sqlite.org/releaselog/3_39_2.htmlRelease NotesVendor Advisory
- https://www.sqlite.org/cves.htmlVendor Advisory
FAQ
What is CVE-2022-35737?
CVE-2022-35737 is a vulnerability with a CVSS score of 7.5 (HIGH). SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.
How severe is CVE-2022-35737?
CVE-2022-35737 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-35737?
Check the references section above for vendor advisories and patch information. Affected products include: Sqlite Sqlite, Netapp Ontap Select Deploy Administration Utility, Splunk Universal Forwarder.