Vulnerability CVE-2020-11655: Information

Description

SQLite through 3.31.1 allows attackers to cause a denial of service (segmentation fault) via a malformed window-function query because the AggInfo object's initialization is mishandled.

Severity: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Published: April 9, 2020
Modified: April 8, 2022
Error type identifier: CWE-665

Fixed packages

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:sqlite:sqlite:*:*:*:*:*:*:*:*
      End including
      3.31.1

      Configuration 2

      cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

      cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

      Configuration 4

      cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*

      Configuration 5

      cpe:2.3:a:oracle:outside_in_technology:8.5.4:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:instantis_enterprisetrack:17.1:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:instantis_enterprisetrack:17.2:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:instantis_enterprisetrack:17.3:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:outside_in_technology:8.5.5:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.1.2.4:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:enterprise_manager_ops_center:12.4.0.0:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*
      Start including
      8.0.0
      End including
      8.0.22

      cpe:2.3:a:oracle:communications_network_charging_and_control:12.0.2:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:communications_network_charging_and_control:6.0.1:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:communications_network_charging_and_control:*:*:*:*:*:*:*:*
      Start including
      12.0.0
      End including
      12.0.3

      cpe:2.3:a:oracle:communications_session_route_manager:*:*:*:*:*:*:*:*
      Start including
      8.2.0
      End including
      8.2.2

      cpe:2.3:a:oracle:communications_session_report_manager:*:*:*:*:*:*:*:*
      Start including
      8.2.0
      End including
      8.2.2

      cpe:2.3:a:oracle:communications_element_manager:*:*:*:*:*:*:*:*
      Start including
      8.2.0
      End including
      8.2.2

      cpe:2.3:a:oracle:zfs_storage_appliance_kit:8.8:*:*:*:*:*:*:*

      cpe:2.3:o:oracle:communications_messaging_server:8.1:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:mysql_workbench:*:*:*:*:*:*:*:*
      End including
      8.0.22

      Configuration 6

      cpe:2.3:a:siemens:sinec_infrastructure_network_services:*:*:*:*:*:*:*:*
      End excliding
      1.0.1.1

      Configuration 7

      cpe:2.3:a:tenable:tenable.sc:*:*:*:*:*:*:*:*
      End excliding
      5.19.0