CVE-2021-20227

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
23/03/2021
Last modified:
16/11/2022

Description

A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on the SQLite database to cause a denial of service or possible code execution by triggering a use-after-free. The highest threat from this vulnerability is to system availability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sqlite:sqlite:*:*:*:*:*:*:*:* 3.33.0 (including) 3.34.1 (excluding)
cpe:2.3:a:oracle:communications_network_charging_and_control:*:*:*:*:*:*:*:* 12.0.1.0 (including) 12.0.4.0.0 (including)
cpe:2.3:a:oracle:communications_network_charging_and_control:6.0.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:enterprise_manager_for_oracle_database:13.4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:*:*:*:*:*:*:*:* 9.2.6.0 (excluding)
cpe:2.3:a:oracle:mysql_workbench:*:*:*:*:*:*:*:* 8.0.26 (including)
cpe:2.3:a:oracle:outside_in_technology:8.5.5:*:*:*:*:*:*:*
cpe:2.3:a:oracle:zfs_storage_appliance_kit:8.8:*:*:*:*:*:*:*