---
title: "CVE-2019-19645\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2019-19645?format=md
keywords: index, follow
---

# CVE-2019-19645

Publication date 9 December 2019

Last updated 25 August 2025

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**5.5 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2019-19645?format=md#impact-score)

Toggle side navigation

## Description

alter.c in SQLite through 3.30.1 allows attackers to trigger infinite
recursion via certain types of self-referential views in conjunction with
ALTER TABLE statements.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2019-19645?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| sqlite | 20.04 LTS focal | Not affected |
| 19.10 eoan | Not affected |
| 19.04 disco | Not affected |
| 18.04 LTS bionic | Not affected |
| 16.04 LTS xenial | Not affected |
| 14.04 LTS trusty | Not affected |
| sqlite3 | 20.04 LTS focal | Not affected |
| 19.10 eoan | Fixed 3.29.0-2ubuntu0.3 |
| 19.04 disco | Ignored end of life |
| 18.04 LTS bionic | Ignored |
| 16.04 LTS xenial | Ignored |
| 14.04 LTS trusty | Ignored end of standard support |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2019-19645?format=md#patch-details)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

The code changes required to backport the fix for this issue to
older versions of SQLite shipped in Ubuntu stable releases is
subtantial and may introduce regressions. Due to the low
severity of this issue, we will not be releasing a fix for
Ubuntu 18.04 LTS and earlier. Marking as ignored.

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| sqlite3 | * Upstream:   [3809696](https://github.com/sqlite/sqlite/commit/38096961c7cd109110ac21d3ed7dad7e0cb0ae06) |

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

5.5 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Local |
  | Attack complexity | Low |
  | Privileges required | Low |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | None |
  | Integrity impact | None |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 5.5 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19645)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2019-19645)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2019-19645)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2019-19645)

### Related Ubuntu Security Notices (USN)

+ [USN-4394-1](https://usn.ubuntu.com/USN-4394-1)
+ SQLite vulnerabilities
+ 10 June 2020

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2019-19645>
