CVE-2019-19242: SQL Injection
Published Nov 25, 2019
·Updated
An unspecified error with the mishandling of pExpr->y.pTab in the sqlite3ExprCodeTarget function in expr.c in SQLite has an unknown impact and attack vector.
Other sources
SQLite 3.30.1 mishandles pExpr->y.pTab, as demonstrated by the TKCOLUMN case in sqlite3ExprCodeTarget in expr.c.
— Launchpad
Affected Software
11 affected componentsFixes available
IBM Data Risk Manager<=2.0.6
SQLite SQLite=3.30.1
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=19.04
Canonical Ubuntu Linux=19.10
redhat Enterprise Linux=8.0
Oracle MySQL Workbench<=8.0.19
Siemens Sinec Infrastructure Network Services<1.0.1.1
debian/sqlite3
3.34.1-33.34.1-3+deb11u13.40.1-2+deb12u23.46.1-7+deb13u13.46.1-9
Remediation
Patch Available
Event History
Nov 25, 2019
CVE Published
via MITRE·03:30 PM
Data Sourced
via MITRE·03:30 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·11:24 PM
Description
Feb 20, 2026
Data Sourced
via Ubuntu·09:14 PM
RemedyDescriptionSeverityAffected Software
Mar 14, 2026
Data Sourced
via Debian·06:57 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2019-19242?
CVE-2019-19242 is a vulnerability in SQLite that mishandles pExpr->y.pTab in the sqlite3ExprCodeTarget function.
2
What is the impact of CVE-2019-19242?
The impact of CVE-2019-19242 is unknown.
3
How can I fix CVE-2019-19242?
To fix CVE-2019-19242, update to a patched version of SQLite or apply the recommended remedy provided by the vendor or the distribution.
4
What is the severity of CVE-2019-19242?
CVE-2019-19242 has a severity rating of 7.3 (high).
5
Where can I find more information about CVE-2019-19242?
You can find more information about CVE-2019-19242 on the MITRE CVE database, Ubuntu Security Notices, and the NVD website.