SQLite before 3.8.9 does not properly implement the dequoting of collation-sequence names, which allows context-dependent attackers to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other impact via a crafted COLLATE clause, as demonstrated by COLLATE"""""""" at the end of a SELECT statement.
2015-04-24T17:59:00.067
2025-04-12T10:46:40.837
Deferred
CVSSv2: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | sqlite | sqlite | ≤ 3.8.8.3 | Yes |
Operating System | apple | mac_os_x | 10.10.5 | Yes |
Operating System | apple | watchos | 1.0.1 | Yes |
Operating System | debian | debian_linux | 8.0 | Yes |
Operating System | canonical | ubuntu_linux | 12.04 | Yes |
Operating System | canonical | ubuntu_linux | 14.04 | Yes |
Operating System | canonical | ubuntu_linux | 15.04 | Yes |
Application | php | php | < 5.4.42 | Yes |
Application | php | php | < 5.5.26 | Yes |
Application | php | php | < 5.6.10 | Yes |