Skip to content
Appaloosa Scout

Vulnerability · NVD

CVE-2018-20346

HIGH 8.1

SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries that occur after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases), aka Magellan.

Attack vector : Network No privileges required No user interaction
Show raw CVSS vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS 9.86% above median percentile 95.1%

OS versions that fix this CVE

This CVE is resolved by the following OS security releases. Update the OS to at least the listed version.

View on NVD ↗ Advisory · www.sqlite.org Advisory · sqlite.org