CVE-2019-20218: SQL Injection
An unspecified error in selectExpander in select.c in SQLite has an unknown impact and attack vector.
Other sources
selectExpander in select.c in SQLite 3.30.1 proceeds with WITH stack unwinding even after a parsing error.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-20218?
CVE-2019-20218 is an unspecified error in selectExpander in SQLite with an unknown impact and attack vector.
What is the severity of CVE-2019-20218?
The severity of CVE-2019-20218 is high with a CVSS score of 7.5.
Which software versions are affected by CVE-2019-20218?
CVE-2019-20218 affects SQLite versions 3.30.1 and earlier, and Debian and Ubuntu distributions with various package versions.
How can I fix CVE-2019-20218 in SQLite?
To fix CVE-2019-20218 in SQLite, upgrade to version 3.30.2 or later.
How can I fix CVE-2019-20218 in Debian and Ubuntu distributions?
To fix CVE-2019-20218 in Debian and Ubuntu distributions, update the 'sqlite', 'sqlite3', or 'sqlite3' packages to the recommended versions provided by the respective vendors.