CVE-2020-13632

Modified
Published: 27 May 2020, 14:42
Last modified:04 Aug 2024, 12:25

Vulnerability Summary

Overall Risk (default)
low
22/100
CVSS Score
5.5 MEDIUM
v3.1 (nvd)
EPSS Score
0.03% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

27 May 2020, 14:42
Published
Vulnerability first disclosed
04 Aug 2024, 12:25
Last Modified
Vulnerability information updated

Description

ext/fts3/fts3_snippet.c in SQLite before 3.32.0 has a NULL pointer dereference via a crafted matchinfo() query.

CVSS Metrics

  • v3.1MEDIUMScore: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
  • v2.0LOWScore: 2.1AV:L/AC:L/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 0.03% Percentile: 9%

Techniques & Countermeasures

  • CWE-476NULL Pointer Dereference

    The product dereferences a pointer that it expects to be valid but is NULL.

Affected Systems

  • brocadefabric_operating_system

    na

  • canonicalubuntu_linux

    16.04 | 18.04 | 19.10 | 20.04

  • debiandebian_linux

    9.0

  • fedoraprojectfedora

    32

  • netappcloud_backup

    na

  • netapphci_compute_node_firmware

    na

  • netappsolidfire\,_enterprise_sds_\&_hci_storage_node

    na

  • oraclecommunications_network_charging_and_control

    ≥ 12.0.0, ≤ 12.0.3 | 6.0.1

  • oracleoutside_in_technology

    8.5.4 | 8.5.5

  • oraclezfs_storage_appliance_kit

    8.8

  • siemenssinec_infrastructure_network_services

    < 1.0.1.1

  • sqlitesqlite

    < 3.32.0

References (11)