Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The getNodeSize function in ext/rtree/rtree.c in SQLite through 3.19.3, as used in GDAL and other products, mishandles undersized RTree blobs in a crafted database, leading to a heap-based buffer over-read or possibly unspecified other impact.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SQLite 缓冲区错误漏洞
Vulnerability Description
SQLite是美国软件开发者D.Richard Hipp所研发的一套基于C语言的开源嵌入式关系数据库管理系统。该系统具有独立性、隔离性、可跨平台等特点。 GDAL和其他产品中的SQLite 3.19.3及之前的版本的ext/rtree/rtree.c文件的‘getNodeSize’功能存在安全漏洞。攻击者可利用该漏洞造成拒绝服务(基于堆的缓冲区越边界读取)。
CVSS Information
N/A
Vulnerability Type
N/A