openwrt ▾
›
openwrt-25.12 ▾
›
vulnerability
›
CVE-2019-8457
Component Overview
Vulnerability Overview
Name
CVE-2019-8457
Source
NVD (
link
)
Debian (
link
)
Description
SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree tables.
CWEs
CWE-125
CWE-125
Published Date
May 30, 2019
Updated Date
Jun 17, 2026
Workaround
-
Advisories
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00074.html
Third Party Advisory
https://security.netapp.com/advisory/ntap-20190606-0002/
Third Party Advisory
https://usn.ubuntu.com/4004-1/
Third Party Advisory
https://usn.ubuntu.com/4004-2/
Third Party Advisory
https://usn.ubuntu.com/4019-1/
Third Party Advisory
https://usn.ubuntu.com/4019-2/
Third Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
Patch
https://www.sqlite.org/releaselog/3_28_0.html
Release Notes
https://www.sqlite.org/src/info/90acdbfce9c08858
Patch
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00074.html
Third Party Advisory
https://security.netapp.com/advisory/ntap-20190606-0002/
Third Party Advisory
https://usn.ubuntu.com/4004-1/
Third Party Advisory
https://usn.ubuntu.com/4004-2/
Third Party Advisory
https://usn.ubuntu.com/4019-1/
Third Party Advisory
https://usn.ubuntu.com/4019-2/
Third Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
Patch
https://www.sqlite.org/releaselog/3_28_0.html
Release Notes
https://www.sqlite.org/src/info/90acdbfce9c08858
Patch
Analysis
#
Affected Component
Analysis
db
Patched
Vulnerability Ratings
#
9.8
CVSSv31
7.5
CVSSv2
Resolved with patches
#
db (openwrt:openwrt-25.12)
#
Title
Author
Resolve
1
Patch #1
Unknown
CVE-2019-8457