Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2019-16168

Description

In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validation of a sqlite_stat1 sz field, aka a "severe division by zero in the query planner."

POC

Reference

- https://kc.mcafee.com/corporate/index?page=content&id=SB10365

- https://www.mail-archive.com/sqlite-users%40mailinglists.sqlite.org/msg116312.html

- https://www.mail-archive.com/sqlite-users@mailinglists.sqlite.org/msg116312.html

- https://www.oracle.com/security-alerts/cpuapr2020.html

- https://www.oracle.com/security-alerts/cpujan2020.html

Github

- https://github.com/Anna-Rafaella/Conteneurisation

- https://github.com/akaganeite/CVE4PP

- https://github.com/fredrkl/trivy-demo

- https://github.com/garethr/snykout

- https://github.com/n0-traces/cve_monitor