SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c.
References
Link Resource
http://seclists.org/fulldisclosure/2020/Dec/32 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2020/Nov/19 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2020/Nov/20 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2020/Nov/22 Mailing List Third Party Advisory
https://lists.debian.org/debian-lts-announce/2020/05/msg00024.html Mailing List Third Party Advisory
https://lists.debian.org/debian-lts-announce/2020/08/msg00037.html Mailing List Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L7KXQWHIY2MQP4LNM6ODWJENMXYYQYBN/
https://security.FreeBSD.org/advisories/FreeBSD-SA-20:22.sqlite.asc Third Party Advisory
https://security.gentoo.org/glsa/202007-26 Third Party Advisory
https://security.netapp.com/advisory/ntap-20200528-0004/ Third Party Advisory
https://support.apple.com/kb/HT211843 Third Party Advisory
https://support.apple.com/kb/HT211844 Third Party Advisory
https://support.apple.com/kb/HT211850 Third Party Advisory
https://support.apple.com/kb/HT211931 Third Party Advisory
https://support.apple.com/kb/HT211935 Third Party Advisory
https://support.apple.com/kb/HT211952 Third Party Advisory
https://usn.ubuntu.com/4394-1/ Third Party Advisory
https://www.oracle.com/security-alerts/cpuApr2021.html Patch Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2022.html Patch Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2020.html Patch Third Party Advisory
https://www.sqlite.org/src/info/23439ea582241138 Exploit Patch Vendor Advisory
https://www.sqlite.org/src/info/d08d3405878d394e Patch Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2020-05-24T21:55:27

Updated: 2022-04-19T23:21:16

Reserved: 2020-05-24T00:00:00


Link: CVE-2020-13434

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2020-05-24T22:15:10.397

Modified: 2023-11-07T03:16:40.363


Link: CVE-2020-13434

JSON object: View

cve-icon Redhat Information

No data.

CWE