Security Advisory

CVE-2019-5018

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2019-05-10 18:46:59
Last updated 2024-08-04 19:40:49
Assigner talos
CVSS score 8.1
State PUBLISHED

Description

An exploitable use after free vulnerability exists in the window function functionality of Sqlite3 3.26.0. A specially crafted SQL command can cause a use after free vulnerability, potentially resulting in remote code execution. An attacker can send a malicious SQL command to trigger this vulnerability.