CVE-2018-20505

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
03/04/2019
Last modified:
19/06/2019

Description

SQLite 3.25.2, when queries are run on a table with a malformed PRIMARY KEY, allows remote attackers to cause a denial of service (application crash) by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sqlite:sqlite:*:*:*:*:*:*:*:* 3.25.2 (including)
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* 12.1.3 (excluding)
cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* 10.14.2 (excluding)
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* 5.1.3 (excluding)
cpe:2.3:a:apple:icloud:*:*:*:*:*:*:*:* 7.10 (excluding)
cpe:2.3:a:apple:itunes:*:*:*:*:*:*:*:* 12.9.3 (excluding)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*