CVE-2019-19925: SQL Injection
Last updated 25 August 2025
Other sources
SQLite is vulnerable to a denial of service, caused by the mishandling of a NULL pathname in the zipfileUpdate function in ext/misc/zipfile.c. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-19925?
CVE-2019-19925 is a vulnerability in SQLite that allows a remote attacker to cause a denial of service by exploiting a mishandling of a NULL pathname.
What is the severity of CVE-2019-19925?
CVE-2019-19925 has a severity rating of 7.5 (high).
How does CVE-2019-19925 affect IBM Data Risk Manager?
IBM Data Risk Manager version 2.0.6 is affected by CVE-2019-19925.
How can I fix CVE-2019-19925 in SQLite?
Apply the patch provided by SQLite or upgrade to a version that has fixed the vulnerability.
Where can I find more information about CVE-2019-19925?
You can find more information about CVE-2019-19925 in the references provided: [link1], [link2], [link3].