CVE-2019-16168
Aliases:DEBIAN-CVE-2019-16168ALPINE-CVE-2019-16168CGA-2xq3-p82w-9c7vCGA-3j7c-wcp4-83j4CGA-7h58-5wp8-m5w7CGA-7xf4-926q-rqfcCGA-98vh-jcff-8qwjCGA-c24r-47hm-h738CGA-cc9x-g7vf-gjmjCGA-cmqv-426f-hwvvCGA-fxcw-2vrw-q429CGA-hw9w-5v86-964wCGA-v5p2-xj2f-mmx8CGA-wp7h-29g9-w2wc
Advisory lineage Upstream: 0 Downstream: 14
Modified
Published: 09 Sept 2019, 16:07
Last modified:28 May 2026, 18:37
Vulnerability Summary
Overall Risk (default)
medium
27/100 CVSS Score
6.5 MEDIUM
v3.1 (nvd)
EPSS Score
4.25% LOW
4% probability +3.41%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
09 Sept 2019, 16:07
Published
Vulnerability first disclosed
28 May 2026, 18:37
Last Modified
Vulnerability information updated
Description
In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validation of a sqlite_stat1 sz field, aka a "severe division by zero in the query planner."
CVSS Metrics
- v3.1•MEDIUM•Score: 6.5CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- v2.0•MEDIUM•Score: 4.3AV:N/AC:M/Au:N/C:N/I:N/A:P
EPSS Trends
Current EPSS score: 4.25%• Percentile: 91%
Techniques & Countermeasures
- CWE-369•Divide By Zero
The product divides a value by zero.
Affected Systems
- alpine•sqlite
≥ 3.8.5, < 3.28.0-r1 | ≥ 3.8.5, < 3.25.3-r2 | ≥ 3.8.5, < 3.28.0-r1
- chainguard•mysql-8.0
< 8.0.38-r0
- chainguard•mysql-8.0-client
< 8.0.38-r0
- chainguard•mysql-8.0-dev
< 8.0.38-r0
- chainguard•mysql-8.0-iamguarded-compat
< 8.0.38-r0
- chainguard•mysql-8.0-oci-entrypoint
< 8.0.38-r0
- chainguard•mysql-8.0-oci-entrypoint-compat
< 8.0.38-r0
- canonical•ubuntu_linux
12.04 | 16.04 | 18.04 | 19.04 | 19.10
- debian•sqlite3
< 3.29.0-2 | < 3.29.0-2 | < 3.29.0-2 | < 3.29.0-2
- debian•debian_linux
9.0
- fedoraproject•fedora
30
- mcafee•policy_auditor
< 6.5.1
- netapp•active_iq_unified_manager
≥ 7.3 | ≥ 9.5
- netapp•e-series_santricity_os_controller
≥ 11.0.0, ≤ 11.60.3
- netapp•oncommand_insight
na
- netapp•oncommand_workflow_automation
na
- netapp•ontap_select_deploy_administration_utility
na
- netapp•santricity_unified_manager
na
- netapp•steelstore_cloud_integrated_storage
na
- oracle•communications_design_studio
7.3.4.3.0 | 7.3.5.5.0 | 7.4.0.4.0
- oracle•jdk
1.8.0:update231
- oracle•jre
1.8.0:update231
- oracle•mysql
≥ 8.0.0, ≤ 8.0.18
- oracle•outside_in_technology
8.5.4
- oracle•solaris
11
- oracle•zfs_storage_appliance
8.8
- sqlite•sqlite
≥ 3.8.5, ≤ 3.29.0
- tenable•nessus_agent
≤ 8.2.3
References (19)
- https://www.mail-archive.com/sqlite-users%40mailinglists.sqlite.org/msg116312.html
- https://www.sqlite.org/src/timeline?c=98357d8c1263920b
- https://www.sqlite.org/src/info/e4598ecbdd18bd82945f6029013296690e719a62
- https://security.netapp.com/advisory/ntap-20190926-0003/
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00033.html
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00032.html
- https://usn.ubuntu.com/4205-1/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XZARJHJJDBHI7CE5PZEBXS5HKK6HXKW2/
- https://www.oracle.com/security-alerts/cpujan2020.html
- https://security.netapp.com/advisory/ntap-20200122-0003/
- https://security.gentoo.org/glsa/202003-16
- https://www.oracle.com/security-alerts/cpuapr2020.html
- https://lists.debian.org/debian-lts-announce/2020/08/msg00037.html
- https://www.tenable.com/security/tns-2021-08
- https://www.tenable.com/security/tns-2021-11
- https://www.tenable.com/security/tns-2021-14
- https://kc.mcafee.com/corporate/index?page=content&id=SB10365
- https://security-tracker.debian.org/tracker/CVE-2019-16168
- https://security.alpinelinux.org/vuln/CVE-2019-16168