Logo
vulnerabilityCVE-2020-15358
Name
CVE-2020-15358
Source
NVD ( link)Debian ( link)
Description
In SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation.
Published Date
Updated Date
Workaround
-
Advisories
https://usn.ubuntu.com/4438-1/Third Party Advisory
https://usn.ubuntu.com/4438-1/Third Party Advisory

Analysis#


Affected Component
Analysis
sqlite
Exploitable

Vulnerability Ratings#


5.5
CVSSv31
2.1
CVSSv2

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
3.50.4
Not Affected
buildroot
master
3.53.2
Not Affected
openwrt
master
3.53.1-r1
Not Affected
openwrt
openwrt-25.12
3.53.1-r1
Not Affected