CVE-2019-19242: SQL Injection
An unspecified error with the mishandling of pExpr->y.pTab in the sqlite3ExprCodeTarget function in expr.c in SQLite has an unknown impact and attack vector.
Other sources
SQLite 3.30.1 mishandles pExpr->y.pTab, as demonstrated by the TKCOLUMN case in sqlite3ExprCodeTarget in expr.c.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/sqlite3to a version that resolves this vulnerability.Fixed in 3.34.1-3Fixed in 3.34.1-3+deb11u1Fixed in 3.40.1-2+deb12u2Fixed in 3.46.1-7+deb13u1Fixed in 3.46.1-9Fixed in 3.53.3-1
Event History
Frequently Asked Questions
What is CVE-2019-19242?
CVE-2019-19242 is a vulnerability in SQLite that mishandles pExpr->y.pTab in the sqlite3ExprCodeTarget function.
What is the impact of CVE-2019-19242?
The impact of CVE-2019-19242 is unknown.
How can I fix CVE-2019-19242?
To fix CVE-2019-19242, update to a patched version of SQLite or apply the recommended remedy provided by the vendor or the distribution.
What is the severity of CVE-2019-19242?
CVE-2019-19242 has a severity rating of 7.3 (high).
Where can I find more information about CVE-2019-19242?
You can find more information about CVE-2019-19242 on the MITRE CVE database, Ubuntu Security Notices, and the NVD website.