CVE-2020-11655

Aliases:ALPINE-CVE-2020-11655DEBIAN-CVE-2020-11655CGA-2pv5-8wmm-f6fgCGA-4wgw-r8hw-99p9CGA-4x3g-289h-8wxrCGA-5h6c-9wpw-8v48CGA-6q8q-cv7p-qwhcCGA-7fxf-pj9q-5h4pCGA-92cf-vmfh-vr3wCGA-h4mv-r677-xc6qCGA-m325-w56m-wgv3CGA-wqc2-5x29-j7m7CGA-ww2w-3p8v-wj2wCGA-xh9p-63gm-2wqp
Modified
Published: 09 Apr 2020, 02:49
Last modified:04 Aug 2024, 11:35

Vulnerability Summary

Overall Risk (default)
medium
41/100
CVSS Score
7.5 HIGH
v3.1 (nvd)
EPSS Score
4.34% LOW
4% probability -0.55%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

09 Apr 2020, 02:49
Published
Vulnerability first disclosed
04 Aug 2024, 11:35
Last Modified
Vulnerability information updated

Description

SQLite through 3.31.1 allows attackers to cause a denial of service (segmentation fault) via a malformed window-function query because the AggInfo object's initialization is mishandled.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 4.34% Percentile: 91%

Techniques & Countermeasures

  • CWE-665Improper Initialization

    The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.

Affected Systems

  • alpinesqlite

    < 3.28.0-r3 | < 3.30.1-r2 | < 3.30.1-r3 | < 3.30.1-r3 | < 3.30.1-r3 | < 3.30.1-r3 | < 3.30.1-r3 | < 3.30.1-r3 | < 3.30.1-r3 | < 3.30.1-r3 | < 3.30.1-r3 | < 3.30.1-r3 | < 3.30.1-r3 | < 3.30.1-r3 | < 3.30.1-r3 | < 3.25.0-r4 | < 3.28.0-r3

  • chainguardmysql-8.0

    < 8.0.38-r0

  • chainguardmysql-8.0-client

    < 8.0.38-r0

  • chainguardmysql-8.0-dev

    < 8.0.38-r0

  • chainguardmysql-8.0-iamguarded-compat

    < 8.0.38-r0

  • chainguardmysql-8.0-oci-entrypoint

    < 8.0.38-r0

  • chainguardmysql-8.0-oci-entrypoint-compat

    < 8.0.38-r0

  • canonicalubuntu_linux

    16.04 | 18.04 | 19.10 | 20.04

  • debiansqlite3

    < 3.31.1-5 | < 3.31.1-5 | < 3.31.1-5 | < 3.31.1-5

  • debiandebian_linux

    8.0 | 9.0

  • netappontap_select_deploy_administration_utility

    na

  • oraclecommunications_element_manager

    ≥ 8.2.0, ≤ 8.2.2

  • oraclecommunications_messaging_server

    8.1

  • oraclecommunications_network_charging_and_control

    ≥ 12.0.0, ≤ 12.0.3 | 6.0.1 | 12.0.2

  • oraclecommunications_session_report_manager

    ≥ 8.2.0, ≤ 8.2.2

  • oraclecommunications_session_route_manager

    ≥ 8.2.0, ≤ 8.2.2

  • oracleenterprise_manager_ops_center

    12.4.0.0

  • oraclehyperion_infrastructure_technology

    11.1.2.4

  • oracleinstantis_enterprisetrack

    17.1 | 17.2 | 17.3

  • oraclemysql

    ≥ 8.0.0, ≤ 8.0.22

  • oraclemysql_workbench

    ≤ 8.0.22

  • oracleoutside_in_technology

    8.5.4 | 8.5.5

  • oraclezfs_storage_appliance_kit

    8.8

  • siemenssinec_infrastructure_network_services

    < 1.0.1.1

  • sqlitesqlite

    ≤ 3.31.1

  • tenabletenable.sc

    < 5.19.0

References (16)