Vulnerability Description
An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sqlite | Sqlite | < 3.51.1 |
Related Weaknesses (CWE)
References
- https://gist.github.com/cnwangjihe/f496393f30f5ecec5b18c8f5ab072054ExploitThird Party Advisory
- https://sqlite.org/forum/forumpost/761eac3c82Issue Tracking
- https://sqlite.org/src/info/3d459f1fb1bd1b5eIssue TrackingPatch
FAQ
What is CVE-2025-70873?
CVE-2025-70873 is a vulnerability with a CVSS score of 7.5 (HIGH). An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.
How severe is CVE-2025-70873?
CVE-2025-70873 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-70873?
Check the references section above for vendor advisories and patch information. Affected products include: Sqlite Sqlite.