High severity8.1OSV Advisory· Published Apr 3, 2019· Updated Jun 17, 2026
CVE-2018-20506
CVE-2018-20506
Description
SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases). This is a different vulnerability than CVE-2018-20346.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
26- osv-coords16 versionspkg:rpm/suse/sqlite3&distro=SUSE%20Enterprise%20Storage%204pkg:rpm/suse/sqlite3&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3pkg:rpm/suse/sqlite3&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP4pkg:rpm/suse/sqlite3&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1-LTSSpkg:rpm/suse/sqlite3&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/sqlite3&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSSpkg:rpm/suse/sqlite3&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3pkg:rpm/suse/sqlite3&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4pkg:rpm/suse/sqlite3&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSSpkg:rpm/suse/sqlite3&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/sqlite3&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/sqlite3&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/sqlite3&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/sqlite3&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3pkg:rpm/suse/sqlite3&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP4pkg:rpm/suse/sqlite3&distro=SUSE%20OpenStack%20Cloud%207
< 3.8.10.2-9.3.1+ 15 more
- (no CPE)range: < 3.8.10.2-9.3.1
- (no CPE)range: < 3.8.10.2-9.3.1
- (no CPE)range: < 3.8.10.2-9.3.1
- (no CPE)range: < 3.8.10.2-9.3.1
- (no CPE)range: < 3.8.10.2-9.3.1
- (no CPE)range: < 3.8.10.2-9.3.1
- (no CPE)range: < 3.8.10.2-9.3.1
- (no CPE)range: < 3.8.10.2-9.3.1
- (no CPE)range: < 3.8.3.1-2.7.1
- (no CPE)range: < 3.8.10.2-9.3.1
- (no CPE)range: < 3.8.10.2-9.3.1
- (no CPE)range: < 3.8.10.2-9.3.1
- (no CPE)range: < 3.8.10.2-9.3.1
- (no CPE)range: < 3.8.10.2-9.3.1
- (no CPE)range: < 3.8.10.2-9.3.1
- (no CPE)range: < 3.8.10.2-9.3.1
Patches
Vulnerability mechanics
References
27- lists.opensuse.org/opensuse-security-announce/2019-04/msg00070.htmlnvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2019/Jan/62nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2019/Jan/64nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2019/Jan/66nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2019/Jan/67nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2019/Jan/68nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2019/Jan/69nvdMailing ListThird Party Advisory
- www.securityfocus.com/bid/106698nvdThird Party AdvisoryVDB Entry
- seclists.org/bugtraq/2019/Jan/28nvdMailing ListThird Party Advisory
- seclists.org/bugtraq/2019/Jan/29nvdMailing ListThird Party Advisory
- seclists.org/bugtraq/2019/Jan/31nvdMailing ListThird Party Advisory
- seclists.org/bugtraq/2019/Jan/32nvdMailing ListThird Party Advisory
- seclists.org/bugtraq/2019/Jan/33nvdMailing ListThird Party Advisory
- seclists.org/bugtraq/2019/Jan/39nvdMailing ListThird Party Advisory
- security.netapp.com/advisory/ntap-20190502-0004/nvdThird Party Advisory
- sqlite.org/src/info/940f2adc8541a838nvdVendor Advisory
- support.apple.com/kb/HT209443nvdThird Party Advisory
- support.apple.com/kb/HT209446nvdThird Party Advisory
- support.apple.com/kb/HT209447nvdThird Party Advisory
- support.apple.com/kb/HT209448nvdThird Party Advisory
- support.apple.com/kb/HT209450nvdThird Party Advisory
- support.apple.com/kb/HT209451nvdThird Party Advisory
- kc.mcafee.com/corporate/indexnvd
- lists.debian.org/debian-lts-announce/2020/08/msg00037.htmlnvd
- usn.ubuntu.com/4019-1/nvd
- usn.ubuntu.com/4019-2/nvd
- www.oracle.com/security-alerts/cpuapr2020.htmlnvd
News mentions
1- ABB B&R Automation StudioCISA ICS Advisories