CVE-2019-19603: SQL Injection
An error during handling of CREATE TABLE and CREATE VIEW statements in SQLite has an unknown impact via a specially crafted table name.
Other sources
SQLite 3.30.1 mishandles certain SELECT statements with a nonexistent VIEW, leading to an application crash.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/sqlite3to a version that resolves this vulnerability.Fixed in 3.34.1-3Fixed in 3.34.1-3+deb11u1Fixed in 3.40.1-2+deb12u2Fixed in 3.46.1-7+deb13u1Fixed in 3.53.3-1 - Upgrade
Upgrade
sqlite/sqliteto a version that resolves this vulnerability.Fixed in 3.30.1Patch https://github.com/sqlite/sqlite/commit/527cbd4a104cb93bf3994b3dd3619a6299a78b13
Event History
Frequently Asked Questions
What is CVE-2019-19603?
CVE-2019-19603 is a vulnerability in SQLite 3.30.1 that mishandles certain SELECT statements with a nonexistent VIEW.
What is the severity of CVE-2019-19603?
The severity of CVE-2019-19603 is high, with a CVSSv3 score of 7.5.
How does CVE-2019-19603 affect IBM Data Risk Manager?
IBM Data Risk Manager 2.0.6 is affected by CVE-2019-19603. A patch is available.
How can I fix CVE-2019-19603 on Ubuntu?
CVE-2019-19603 can be fixed on Ubuntu by updating to version 3.29.0-2ubuntu0.3 or later of the sqlite3 package.
Is there a fix for CVE-2019-19603 on Debian?
Yes, a fix is available for CVE-2019-19603 on Debian by updating to the latest version of the sqlite3 package.