Skip to main content

CVE-2019-19244

CVE Details

Visit the official vulnerability details page for CVE-2019-19244 to learn more.

Initial Publication

10/25/2024

Last Update

10/25/2024

Third Party Dependency

sqlite-libs

NIST CVE Summary

sqlite3Select in select.c in SQLite 3.30.1 allows a crash if a sub-select uses both DISTINCT and window functions, and also has certain ORDER BY usage.

CVE Severity

7.5

Our Official Summary

This vulnerability found in SQLite can be remotely exploited by sending sql queries with DISTINCT, OVER and ORDER BY clauses. This will cause application crashes causing a denial of service attack.

Containers where this vulnerability is reported do not allow access to the sqlite database without an attacker gaining privileged access to the images. Even then risk of exploitation is low since there are controls to prevent execution of arbitrary commands.

Status

Ongoing

Affected Products & Versions

VersionPalette EnterprisePalette Enterprise AirgapVerteXVerteX Airgap
4.5.11ImpactedNo ImpactImpactedNo Impact
4.5.10ImpactedNo ImpactImpactedNo Impact
4.5.8ImpactedNo ImpactImpactedNo Impact
4.5.5ImpactedNo ImpactImpactedNo Impact
4.5.4ImpactedNo ImpactImpactedNo Impact
4.4.20ImpactedNo ImpactImpactedNo Impact

Revision History

DateRevision
12/04/2024Official summary revised: This vulnerability found in SQLite can be remotely exploited by sending sql queries with DISTINCT, OVER and ORDER BY clauses. This will cause application crashes causing a denial of serviceattack. Containers where this vulnerability is reported do not allow access to the sqlite database without an attacker gaining privileged access to the images. Even then risk of exploitation is lowsince there are controls to prevent execution of arbitrary commands.
11/15/2024Impacted versions changed from 4.5.4, 4.5.5, 4.5.8, 4.4.20, 4.5.10 to 4.5.4, 4.5.5, 4.5.8, 4.4.20, 4.5.10, 4.5.11
11/15/2024Impacted versions changed from 4.5.4, 4.5.5, 4.5.8, 4.4.20 to 4.5.4, 4.5.5, 4.5.8, 4.4.20, 4.5.10
11/13/2024Impacted versions changed from 4.5.4, 4.5.5, 4.5.8 to 4.5.4, 4.5.5, 4.5.8, 4.4.20
11/10/2024Impacted versions changed from 4.5.4, 4.5.5 to 4.5.4, 4.5.5, 4.5.8
10/27/2024Impacted versions changed from 4.5.4 to 4.5.4, 4.5.5