« List of all CVEs

CVE-2020-15358

Published: 6/27/2020 Last updated: 8/4/2024 Reserved: 6/27/2020

In SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation.

CNA assigner: mitre (8254265b-2729-46b6-b9e3-3dfca2d5bfca) Requested by: n/a

Opam packages affected (5)

conf-mingw-w64-sqlite3-i686 conf-mingw-w64-sqlite3-x86_64 conf-mysql conf-sqlite3 lemonade-sqlite

Products affected (1)

Product Vendor Version
n/a n/a < 10.0.19045.2486

References (44)