CVE-2025-3277
Published:
4/14/2025
Last updated:
5/27/2025
Reserved:
4/4/2025
An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used to allocate a buffer. When SQLite then writes the resulting string to the buffer, it uses the original, untruncated size and thus a wild Heap Buffer overflow of size ~4GB can be triggered. This can result in arbitrary code execution.
CNA assigner:
Google (14ed7db2-1595-443d-9d34-6215bf890778)
Requested by:
n/a
Products affected (1)
| Product |
Vendor |
Version |
| sqlite |
SQLite
|
<= 2.6.3
|