Search CVE reports
1 – 3 of 3 results
Zetetic SQLCipher 4.x before 4.4.3 has a NULL pointer dereferencing issue related to sqlcipher_export in crypto.c and sqlite3StrICmp in sqlite3.c. This may allow an attacker to perform a remote denial of service attack. For...
1 affected package
sqlcipher
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
sqlcipher | — | — | Not affected | Not affected |
Zetetic SQLCipher 4.x before 4.4.1 has a use-after-free, related to sqlcipher_codec_pragma and sqlite3Strlen30 in sqlite3.c. A remote denial of service attack can be performed. For example, a SQL injection can be used to execute...
1 affected package
sqlcipher
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
sqlcipher | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
Some fixes available 34 of 65
SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree tables.
5 affected packages
sqlite3, db5.3, chromium, qtwebengine-opensource-src, sqlcipher
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
sqlite3 | Fixed | Fixed | Fixed | Fixed |
db5.3 | Fixed | Fixed | Fixed | Fixed |
chromium | Not in release | Not in release | Not in release | Not in release |
qtwebengine-opensource-src | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
sqlcipher | Vulnerable | Vulnerable | Vulnerable | Vulnerable |