Vulnerability CVE-2019-19926: Information

Description

multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsing, as demonstrated by errors from sqlite3WindowRewrite() calls. NOTE: this vulnerability exists because of an incomplete fix for CVE-2019-19880.

Severity: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Published: Dec. 23, 2019
Modified: April 15, 2022
Error type identifier: CWE-476

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
chromiumsisyphus80.0.3987.132-alt1125.0.6422.141-alt1ALT-PU-2020-1457-1247705Fixed
chromiump1080.0.3987.132-alt1119.0.6045.159-alt0.p10.1ALT-PU-2020-1457-1247705Fixed
chromiump980.0.3987.132-alt197.0.4692.99-alt0.p9.1ALT-PU-2020-1521-1247789Fixed
chromiumc10f180.0.3987.132-alt1110.0.5481.177-alt1.p10.1ALT-PU-2020-1457-1247705Fixed
chromiumc9f280.0.3987.132-alt184.0.4147.105-alt1.1.p9ALT-PU-2020-1521-1247789Fixed
chromiump1180.0.3987.132-alt1125.0.6422.141-alt1ALT-PU-2020-1457-1247705Fixed
chromium-gostsisyphus80.0.3987.132-alt1124.0.6367.78-alt1ALT-PU-2020-1707-1249793Fixed
chromium-gostp1080.0.3987.132-alt1110.0.5481.177-alt1.p10.1ALT-PU-2020-1707-1249793Fixed
chromium-gostp983.0.4103.61-alt2.M90P.196.0.4664.45-alt2.p9.1ALT-PU-2020-2441-1255237Fixed
chromium-gostc10f180.0.3987.132-alt1110.0.5481.177-alt1.p10.1ALT-PU-2020-1707-1249793Fixed
chromium-gostc9f283.0.4103.61-alt2.M90P.196.0.4664.45-alt2.c9.1ALT-PU-2020-2441-1255237Fixed
chromium-gostp1180.0.3987.132-alt1124.0.6367.78-alt1ALT-PU-2020-1707-1249793Fixed
mysql-workbench-communitysisyphus8.0.20-alt18.0.33-alt2.2ALT-PU-2020-2094-1252776Fixed
mysql-workbench-communityp108.0.20-alt18.0.25-alt2ALT-PU-2020-2094-1252776Fixed
mysql-workbench-communityp98.0.20-alt18.0.25-alt2ALT-PU-2020-2183-1252777Fixed
mysql-workbench-communityc10f18.0.20-alt18.0.25-alt2ALT-PU-2020-2094-1252776Fixed
mysql-workbench-communityc9f28.0.20-alt18.0.25-alt3ALT-PU-2020-2183-1252777Fixed
mysql-workbench-communityp118.0.20-alt18.0.33-alt2.2ALT-PU-2020-2094-1252776Fixed
sqlite3sisyphus3.31.0-alt13.44.2-alt1ALT-PU-2020-1088-1244880Fixed
sqlite3p103.31.0-alt13.35.5-alt1.p10.1ALT-PU-2020-1088-1244880Fixed
sqlite3p93.33.0-alt13.33.0-alt1ALT-PU-2020-2898-1258834Fixed
sqlite3c10f13.31.0-alt13.35.5-alt1.p10.1ALT-PU-2020-1088-1244880Fixed
sqlite3c9f23.33.0-alt13.36.0-alt2ALT-PU-2020-2898-1258834Fixed
sqlite3p113.31.0-alt13.44.2-alt1ALT-PU-2020-1088-1244880Fixed

References to Advisories, Solutions, and Tools

Hyperlink
Resource
https://github.com/sqlite/sqlite/commit/8428b3b437569338a9d1e10c4cd8154acbe33089
  • Patch
  • Third Party Advisory
https://security.netapp.com/advisory/ntap-20200114-0003/
  • Third Party Advisory
openSUSE-SU-2020:0189
  • Mailing List
  • Third Party Advisory
openSUSE-SU-2020:0210
  • Mailing List
  • Third Party Advisory
RHSA-2020:0514
  • Third Party Advisory
openSUSE-SU-2020:0233
  • Mailing List
  • Third Party Advisory
DSA-4638
  • Third Party Advisory
USN-4298-1
  • Broken Link
N/A
  • Patch
  • Third Party Advisory
USN-4298-2
  • Broken Link
https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
  • Patch
  • Third Party Advisory
    1. Configuration 1

      cpe:2.3:a:sqlite:sqlite:3.30.1:*:*:*:*:*:*:*

      Configuration 2

      cpe:2.3:a:siemens:sinec_infrastructure_network_services:*:*:*:*:*:*:*:*
      End excliding
      1.0.1.1

      Configuration 3

      cpe:2.3:a:oracle:mysql_workbench:*:*:*:*:*:*:*:*
      End including
      8.0.19

      Configuration 4

      cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

      cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

      Configuration 5

      cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*

      Configuration 6

      cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*

      cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:*

      Configuration 7

      cpe:2.3:a:suse:package_hub:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:suse:linux_enterprise:12.0:*:*:*:*:*:*:*

      Configuration 8

      cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*