Logo
vulnerabilityCVE-2018-20506
Name
CVE-2018-20506
Source
NVD ( link)Debian ( link)
Description
SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases). This is a different vulnerability than CVE-2018-20346.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
sqlite
Exploitable

Vulnerability Ratings#


8.1
other
6.8
CVSSv2

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
3.50.4
Not Affected
buildroot
master
3.53.2
Not Affected
openwrt
master
3.53.1-r1
Not Affected
openwrt
openwrt-25.12
3.53.1-r1
Not Affected