• 公告ID (KylinSec-SA-2022-1422)

摘要:

** DISPUTED ** A segmentation fault can occur in the sqlite3.exe command-line component of SQLite 3.36.0 via the idxGetTableInfo function when there is a crafted SQL query. NOTE: the vendor disputes the relevance of this report because a sqlite3.exe user already has full privileges (e.g., is intentionally allowed to execute commands). This report does NOT imply any problem in the SQLite library.

安全等级: Low

公告ID: KylinSec-SA-2022-1422

发布日期: 2022年7月22日

关联CVE: CVE-2021-36690  

  • 详细介绍

1. 漏洞描述

   

** DISPUTED ** A segmentation fault can occur in the sqlite3.exe command-line component of SQLite 3.36.0 via the idxGetTableInfo function when there is a crafted SQL query. NOTE: the vendor disputes the relevance of this report because a sqlite3.exe user already has full privileges (e.g., is intentionally allowed to execute commands). This report does NOT imply any problem in the SQLite library.

2. 影响范围

cve名称 产品 组件 是否受影响
CVE-2021-36690 KY3.4-4A sqlite Unaffected
CVE-2021-36690 KY3.4-5 sqlite Unaffected
CVE-2021-36690 KY3.5.1 sqlite Unaffected

3. 影响组件

    无

4. 修复版本

    无

5. 修复方法

   无

6. 下载链接

    无
上一篇:KylinSec-SA-2022-1420 下一篇:KylinSec-SA-2022-1633