An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of service or disclose sensitive information from process memory via a crafted SELECT statement with a large number of expressions in the ORDER BY clause.
{ "binaries": [ { "binary_version": "2.8.17-10ubuntu2", "binary_name": "libsqlite-tcl" }, { "binary_version": "2.8.17-10ubuntu2", "binary_name": "libsqlite0" }, { "binary_version": "2.8.17-10ubuntu2", "binary_name": "libsqlite0-dev" }, { "binary_version": "2.8.17-10ubuntu2", "binary_name": "sqlite" } ] }
{ "binaries": [ { "binary_version": "2.8.17-12fakesync1", "binary_name": "libsqlite-tcl" }, { "binary_version": "2.8.17-12fakesync1", "binary_name": "libsqlite0" }, { "binary_version": "2.8.17-12fakesync1", "binary_name": "libsqlite0-dev" }, { "binary_version": "2.8.17-12fakesync1", "binary_name": "sqlite" } ] }
{ "binaries": [ { "binary_version": "2.8.17-14fakesync1", "binary_name": "libsqlite-tcl" }, { "binary_version": "2.8.17-14fakesync1", "binary_name": "libsqlite0" }, { "binary_version": "2.8.17-14fakesync1", "binary_name": "libsqlite0-dev" }, { "binary_version": "2.8.17-14fakesync1", "binary_name": "sqlite" } ] }
{ "binaries": [ { "binary_version": "2.8.17-15fakesync1build1", "binary_name": "libsqlite-tcl" }, { "binary_version": "2.8.17-15fakesync1build1", "binary_name": "libsqlite0" }, { "binary_version": "2.8.17-15fakesync1build1", "binary_name": "libsqlite0-dev" }, { "binary_version": "2.8.17-15fakesync1build1", "binary_name": "sqlite" } ] }
{ "binaries": [ { "binary_version": "2.8.17-15fakesync1build1", "binary_name": "libsqlite-tcl" }, { "binary_version": "2.8.17-15fakesync1build1", "binary_name": "libsqlite0" }, { "binary_version": "2.8.17-15fakesync1build1", "binary_name": "libsqlite0-dev" }, { "binary_version": "2.8.17-15fakesync1build1", "binary_name": "sqlite" } ] }