HomeSqliteCVE-2019-16168

CVE-2019-16168

MEDIUM
6.5CVSS
Published: 2019-09-09
Updated: 2024-11-21
AI Analysis

Description

In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validation of a sqlite_stat1 sz field, aka a "severe division by zero in the query planner."

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Attack Vector
network
Complexity
low
Privileges
none
User Action
required
Scope
unchanged
Confidentiality
none
Integrity
none
Availability
high
Weaknesses
CWE-369

Metadata

Primary Vendor
SQLITE
Published
9/9/2019
Last Modified
11/21/2024
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

sqlite : sqlitenetapp : active_iq_unified_managernetapp : active_iq_unified_managernetapp : e-series_santricity_os_controllernetapp : oncommand_insightnetapp : oncommand_workflow_automationnetapp : ontap_select_deploy_administration_utilitynetapp : santricity_unified_managernetapp : steelstore_cloud_integrated_storagecanonical : ubuntu_linuxcanonical : ubuntu_linuxcanonical : ubuntu_linuxcanonical : ubuntu_linuxcanonical : ubuntu_linuxfedoraproject : fedoradebian : debian_linuxtenable : nessus_agentoracle : communications_design_studiooracle : communications_design_studiooracle : communications_design_studiooracle : jdkoracle : jreoracle : mysqloracle : outside_in_technologyoracle : solarisoracle : zfs_storage_appliancemcafee : policy_auditor

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2019-16168 | MEDIUM Severity | CVEDatabase.com | CVEDatabase.com