CVE-2019-9936 PUBLISHED

In SQLite 3.27.2, running fts5 prefix queries inside a transaction could trigger a heap-based buffer over-read in fts5HashEntrySort in sqlite3.c, which may lead to an information leak. This is related to ext/fts5/fts5_hash.c.

EPSS 4.54% · 89.1th percentile

Risk Scores

EPSS Score
4.54%
89.1th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSsqlite30, 3.8.11.1-1, 3.9.1-2
Ubuntu:18.04:LTSsqlite30, 3.19.3-3, 3.20.1-2

Timeline

References

Open in Interactive Console →