Unrated severityNVD Advisory· Published Jun 6, 2020· Updated Aug 4, 2024
CVE-2020-13871
CVE-2020-13871
Description
SQLite 3.32.2 has a use-after-free in resetAccumulator in select.c because the parse tree rewrite for window functions is too late.
Affected products
2- SQLite/SQLitedescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BN32AGQPMHZRNM6P6L5GZPETOWTGXOKP/mitrevendor-advisoryx_refsource_FEDORA
- security.gentoo.org/glsa/202007-26mitrevendor-advisoryx_refsource_GENTOO
- cert-portal.siemens.com/productcert/pdf/ssa-389290.pdfmitrex_refsource_CONFIRM
- lists.debian.org/debian-lts-announce/2020/08/msg00037.htmlmitremailing-listx_refsource_MLIST
- security.netapp.com/advisory/ntap-20200619-0002/mitrex_refsource_CONFIRM
- www.oracle.com/security-alerts/cpuApr2021.htmlmitrex_refsource_MISC
- www.oracle.com/security-alerts/cpujan2021.htmlmitrex_refsource_MISC
- www.sqlite.org/src/info/79eff1d0383179c4mitrex_refsource_MISC
- www.sqlite.org/src/info/c8d3b9f0a750a529mitrex_refsource_MISC
- www.sqlite.org/src/info/cd708fa84d2aaaeamitrex_refsource_MISC
News mentions
0No linked articles in our index yet.