CVE-2019-19603: SQL Injection
Published Dec 9, 2019
·Updated
An error during handling of CREATE TABLE and CREATE VIEW statements in SQLite has an unknown impact via a specially crafted table name.
Other sources
SQLite 3.30.1 mishandles certain SELECT statements with a nonexistent VIEW, leading to an application crash.
— MITRE
Affected Software
9 affected componentsFixes available
IBM Data Risk Manager<=2.0.6
SQLite SQLite=3.30.1
Oracle MySQL Workbench<=8.0.19
Siemens Sinec Infrastructure Network Services<1.0.1.1
Siemens Sinec Infrastructure Network Services=1.0.1.1
Apache Guacamole=1.3.0
NetApp Cloud Backup
NetApp ONTAP Select Deploy administration utility
debian/sqlite3
3.34.1-33.34.1-3+deb11u13.40.1-2+deb12u23.46.1-7+deb13u13.46.1-9
Remediation
Patch Available
Event History
Dec 9, 2019
CVE Published
via MITRE·06:44 PM
Data Sourced
via MITRE·06:44 PM
Description
Dec 19, 2019
Data Sourced
via Red Hat·05:05 PM
DescriptionSeverityAffected Software
Feb 20, 2026
Data Sourced
via Ubuntu·09:14 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·09:14 PM
Description
Mar 14, 2026
Data Sourced
via Debian·06:55 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2019-19603?
CVE-2019-19603 is a vulnerability in SQLite 3.30.1 that mishandles certain SELECT statements with a nonexistent VIEW.
2
What is the severity of CVE-2019-19603?
The severity of CVE-2019-19603 is high, with a CVSSv3 score of 7.5.
3
How does CVE-2019-19603 affect IBM Data Risk Manager?
IBM Data Risk Manager 2.0.6 is affected by CVE-2019-19603. A patch is available.
4
How can I fix CVE-2019-19603 on Ubuntu?
CVE-2019-19603 can be fixed on Ubuntu by updating to version 3.29.0-2ubuntu0.3 or later of the sqlite3 package.
5
Is there a fix for CVE-2019-19603 on Debian?
Yes, a fix is available for CVE-2019-19603 on Debian by updating to the latest version of the sqlite3 package.