CVE-2015-3415
Publication date 24 April 2015
Last updated 24 July 2024
Ubuntu priority
The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly implement comparison operators, which allows context-dependent attackers to cause a denial of service (invalid free operation) or possibly have unspecified other impact via a crafted CHECK clause, as demonstrated by CHECK(0&O>O) in a CREATE TABLE statement.
Status
Package | Ubuntu Release | Status |
---|---|---|
sqlite | ||
18.04 LTS bionic |
Not affected
|
|
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty |
Not affected
|
|
sqlite3 | ||
18.04 LTS bionic |
Not affected
|
|
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty |
Not affected
|
|
Patch details
Package | Patch details |
---|---|
sqlite3 |
References
Related Ubuntu Security Notices (USN)
- USN-2698-1
- SQLite vulnerabilities
- 30 July 2015