Vulnerability CVE-2020-11656: Information

Description

In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a compound SELECT statement.

Severity: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Published: April 9, 2020
Modified: April 8, 2022
Error type identifier: CWE-416

Fixed packages

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:sqlite:sqlite:*:*:*:*:*:*:*:*
      End including
      3.31.1

      Configuration 2

      cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:a:oracle:outside_in_technology:8.5.4:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:outside_in_technology:8.5.5:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.1.2.4:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:enterprise_manager_ops_center:12.4.0.0:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*
      Start including
      8.0.0
      End including
      8.0.22

      cpe:2.3:a:oracle:communications_network_charging_and_control:12.0.2:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:communications_network_charging_and_control:6.0.1:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:communications_network_charging_and_control:*:*:*:*:*:*:*:*
      Start including
      12.0.0
      End including
      12.0.3

      cpe:2.3:a:oracle:zfs_storage_appliance_kit:8.8:*:*:*:*:*:*:*

      cpe:2.3:o:oracle:communications_messaging_server:8.1:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:mysql_workbench:*:*:*:*:*:*:*:*
      End including
      8.0.22

      Configuration 4

      cpe:2.3:a:siemens:sinec_infrastructure_network_services:*:*:*:*:*:*:*:*
      End excliding
      1.0.1.1

      Configuration 5

      cpe:2.3:a:tenable:tenable.sc:*:*:*:*:*:*:*:*
      End including
      5.19.0