Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
SQLite before 3.53.2 Memory Corruption in FTS5 Extension
Vulnerability Description
SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. Attackers can trigger an out-of-bounds read in fts5LeafSeek() via an attacker-controlled loop bound and a heap buffer overflow write in fts5ChunkIterate() through a crafted continuation page causing an integer underflow, exploitable when an FTS5 MATCH query is executed against the malicious database.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vulnerability Type
堆缓冲区溢出
Vulnerability Title
SQLite 安全漏洞
Vulnerability Description
SQLite是SQLite开源的一款轻型的数据库,是遵守ACID的关系型数据库管理系统。 SQLite 3.53.2之前版本存在安全漏洞,该漏洞源于FTS5全文搜索扩展中的内存损坏问题,可能导致攻击者通过提供带有畸形FTS5页面数据的特制数据库造成进程崩溃、内存耗尽或任意代码执行。以下版本受到影响:3.53.2之前版本。
CVSS Information
N/A
Vulnerability Type
N/A