CVE-2020-13434: SQL Injection
Last updated 25 August 2025
Other sources
SQLite is vulnerable to a denial of service, caused by an integer overflow in the sqlite3strvappendf function. By sending a specially-crafted request, a remote attacker could overflow a buffer and cause a denial of service.
— IBM
SQLite through 3.32.0 has an integer overflow in sqlite3strvappendf in printf.c.
— Launchpad
SQLite. This issue was addressed with improved checks.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/sqliteto a version that resolves this vulnerability.Fixed in 3.32.1 - Upgrade
Upgrade
Apple macOSto a version that resolves this vulnerability.Fixed in 11.0.1 - Upgrade
Upgrade
tvOSto a version that resolves this vulnerability.Fixed in 14.0 - Upgrade
Upgrade
Apple iOS, iPadOS, and watchOSto a version that resolves this vulnerability.Fixed in 7.0 - Upgrade
Upgrade
Apple iCloudto a version that resolves this vulnerability.Fixed in 11.5 - Upgrade
Upgrade
iTunesto a version that resolves this vulnerability.Fixed in 12.10.9 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 14.0 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 14.0 - Upgrade
Upgrade
debian/sqlite3to a version that resolves this vulnerability.Fixed in 3.34.1-3Fixed in 3.34.1-3+deb11u1Fixed in 3.40.1-2+deb12u2Fixed in 3.46.1-7+deb13u1Fixed in 3.53.3-1 - Upgrade
Upgrade
sqliteto a version that resolves this vulnerability.Fixed in 3.32.0 - Compensating control
Mitigate the denial of service by restricting or filtering any network access that can reach the service using SQLite, until the SQLite integer-overflow fix (improved checks in sqlite3_str_vappendf) is applied.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2020-27914
- CVE-2020-27915
- CVE-2020-27903
- CVE-2020-27910
- CVE-2020-27916
- CVE-2020-9943
- CVE-2020-9944
- CVE-2020-27906
- CVE-2020-27945
- CVE-2020-27908
- CVE-2020-27909
- CVE-2020-9960
- CVE-2020-10017
- CVE-2020-9949
- CVE-2020-9897
- CVE-2020-9883
- CVE-2020-10003
- CVE-2020-27922
- CVE-2020-9999
- CVE-2020-27937
- CVE-2020-9965
- CVE-2020-9966
- CVE-2020-27894
- CVE-2020-36615
- CVE-2021-1790
- CVE-2021-1775
- CVE-2020-29629
- CVE-2020-27942
- CVE-2020-9962
- CVE-2020-27952
- CVE-2020-9956
- CVE-2020-27931
- CVE-2020-27930
- CVE-2020-27927
- CVE-2020-29639
- CVE-2020-10002
- CVE-2020-9978
- CVE-2020-9955
- CVE-2020-27924
- CVE-2020-27912
- CVE-2020-27923
- CVE-2020-9876
- CVE-2020-10015
- CVE-2020-27897
- CVE-2020-27907
- CVE-2020-27919
- CVE-2020-9967
- CVE-2020-9975
- CVE-2020-27921
- CVE-2020-27904
- CVE-2019-14899
- CVE-2020-27950
- CVE-2020-9974
- CVE-2020-10016
- CVE-2020-27932
- CVE-2020-27917
- CVE-2020-27920
- CVE-2020-27911
- CVE-2020-9971
- CVE-2020-10014
- CVE-2020-10010
- CVE-2020-9941
- CVE-2020-9988
- CVE-2020-9989
- CVE-2020-10011
- CVE-2020-13524
- CVE-2020-10004
- CVE-2020-9996
- CVE-2020-27901
- CVE-2020-27900
- CVE-2019-20838
- CVE-2020-14155
- CVE-2020-10007
- CVE-2020-27896
- CVE-2020-9963
- CVE-2020-10012
- CVE-2020-10663
- CVE-2020-9945
- CVE-2020-9977
- CVE-2020-9942
- CVE-2020-9987
- CVE-2021-1803
- CVE-2020-9969
- CVE-2020-27893
- CVE-2021-1755
- CVE-2020-10005
- CVE-2020-9991
- CVE-2020-9849
- CVE-2020-15358
- CVE-2020-13631
- CVE-2020-13434
- CVE-2020-13435
- CVE-2020-13630
- CVE-2020-27899
- CVE-2020-10009
- CVE-2020-10008
- CVE-2020-27918
- CVE-2020-9947
- CVE-2020-9950
- CVE-2020-27898
- CVE-2020-27935
- CVE-2020-10006
- CVE-2020-9979
- CVE-2020-9954
- CVE-2020-36521
- CVE-2020-9961
- CVE-2020-9976
- CVE-2020-9981
- CVE-2020-9968
- CVE-2020-9951
- CVE-2020-9983
- CVE-2020-9952
- CVE-2020-10013
- CVE-2020-9946
- CVE-2020-9993
- CVE-2020-9958
- CVE-2020-9773
- CVE-2020-9992
- CVE-2020-9964
- CVE-2020-13520
- CVE-2020-6147
- CVE-2020-9972
- CVE-2020-9973
- CVE-2020-9959
Frequently Asked Questions
What is CVE-2020-13434?
CVE-2020-13434 is a vulnerability in SQLite that was addressed with improved checks.
Which Apple products are affected by CVE-2020-13434?
CVE-2020-13434 affects Apple tvOS 14.0, Apple macOS Big Sur 11.0.1, Apple iOS 14.0, Apple iPadOS 14.0, Apple watchOS 7.0, Apple iTunes for Windows 12.10.9, and Apple iCloud for Windows 11.5.
How severe is CVE-2020-13434?
The severity of CVE-2020-13434 is not specified in the provided information.
How can I fix CVE-2020-13434?
To fix CVE-2020-13434, update your Apple product to the recommended remedy version mentioned in the affected software section.
Where can I find more information about CVE-2020-13434?
You can find more information about CVE-2020-13434 on the following Apple support pages: [link1], [link2], [link3].