CVE-2019-19923 PUBLISHED

flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which the right-hand side is a view. This can cause a NULL pointer dereference (or incorrect results).

EPSS 6.20% · 90.8th percentile

Risk Scores

EPSS Score
6.20%
90.8th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSsqlite30, 3.19.3-3, 3.20.1-2

Timeline

References

Open in Interactive Console →