CVE-2019-19959 PUBLISHED

ext/misc/zipfile.c in SQLite 3.30.1 mishandles certain uses of INSERT INTO in situations involving embedded '\0' characters in filenames, leading to a memory-management error that can be detected by (for example) valgrind.

EPSS 0.52% · 66.6th percentile

Risk Scores

EPSS Score
0.52%
66.6th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSsqlite30, 3.19.3-3, 3.20.1-2

Timeline

References

Open in Interactive Console →