CVE-2015-3415
Publication date 24 April 2015
Last updated 24 July 2024
Ubuntu priority
Description
The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly implement comparison operators, which allows context-dependent attackers to cause a denial of service (invalid free operation) or possibly have unspecified other impact via a crafted CHECK clause, as demonstrated by CHECK(0&O>O) in a CREATE TABLE statement.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| sqlite | ||
| 18.04 LTS bionic |
Not affected
|
|
| sqlite3 | ||
| 18.04 LTS bionic |
Not affected
|
|
Patch details
| Package | Patch details |
|---|---|
| sqlite3 |
References
Related Ubuntu Security Notices (USN)
- USN-2698-1
- SQLite vulnerabilities
- 30 July 2015