Vulnerability Name:

CVE-2019-9937 (CCN-158903)

Assigned:2019-03-18
Published:2019-03-18
Updated:2020-08-23
Summary:In SQLite 3.27.2, interleaving reads and writes in a single transaction with an fts5 virtual table will lead to a NULL Pointer Dereference in fts5ChunkIterate in sqlite3.c. This is related to ext/fts5/fts5_hash.c and ext/fts5/fts5_index.c.
CVSS v3 Severity:7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
6.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
4.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-476
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2019-9937

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2019:1372

Source: BID
Type: Third Party Advisory, VDB Entry
107562

Source: XF
Type: UNKNOWN
sqlite-cve20199937-dos(158903)

Source: MLIST
Type: UNKNOWN
[debian-lts-announce] 20200822 [SECURITY] [DLA 2340-1] sqlite3 security update

Source: FEDORA
Type: UNKNOWN
FEDORA-2019-8641591b3c

Source: FEDORA
Type: UNKNOWN
FEDORA-2019-a01751837d

Source: GENTOO
Type: UNKNOWN
GLSA-201908-09

Source: CONFIRM
Type: Third Party Advisory
https://security.netapp.com/advisory/ntap-20190416-0005/

Source: CCN
Type: SQLite: Check-in [45c73deb]
Fix an fts5 problem with interleaving reads and writes in a single transaction.

Source: MISC
Type: Patch, Vendor Advisory
https://sqlite.org/src/info/45c73deb440496e8

Source: UBUNTU
Type: UNKNOWN
USN-4019-1

Source: CCN
Type: IBM Security Bulletin 958035 (Security Guardium)
Guardium StealthBits Integration is affected by an SQLite vulnerability

Source: CCN
Type: IBM Security Bulletin 1143496 (Watson Studio Local)
Multiple Vulnerabilities in SQLite affects IBM Watson Studio Local

Source: CCN
Type: SQLite Mailing List, Mon, 18 Mar 2019 03:47:02 -0700
[sqlite] FTS5 Transaction Leads to NULL Pointer

Source: MISC
Type: Exploit, Mailing List, Third Party Advisory
https://www.mail-archive.com/sqlite-users@mailinglists.sqlite.org/msg114383.html

Source: MISC
Type: Mailing List, Patch, Third Party Advisory
https://www.mail-archive.com/sqlite-users@mailinglists.sqlite.org/msg114393.html

Source: MISC
Type: UNKNOWN
https://www.oracle.com/security-alerts/cpujan2020.html

Source: MISC
Type: UNKNOWN
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html

Vulnerable Configuration:Configuration 1:
  • cpe:/a:sqlite:sqlite:3.27.2:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:sqlite:sqlite:3.27.2:*:*:*:*:*:*:*
  • AND
  • cpe:/a:ibm:security_guardium:10.1.4:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:security_guardium:10.6:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20199937
    V
    CVE-2019-9937
    2023-06-22
    oval:org.opensuse.security:def:7675
    P
    libsqlite3-0-3.39.3-150000.3.20.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:797
    P
    Security update for libgit2 (Important)
    2022-10-04
    oval:org.opensuse.security:def:3161
    P
    libcares2-1.9.1-9.4.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3173
    P
    libfreetype6-2.6.3-7.15.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3083
    P
    gnome-keyring-3.20.0-28.3.18 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94713
    P
    libsqlite3-0-3.36.0-3.12.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:203
    P
    libsqlite3-0-3.28.0-3.9.2 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:487
    P
    Security update for php7 (Low)
    2022-05-18
    oval:org.opensuse.security:def:93853
    P
    (Moderate)
    2022-03-24
    oval:org.opensuse.security:def:112849
    P
    libsqlite3-0-3.36.0-1.2 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:1295
    P
    Security update for the Linux Kernel (Live Patch 0 for SLE 15 SP3) (Important)
    2021-12-15
    oval:org.opensuse.security:def:1132
    P
    Security update for go1.17 (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:106312
    P
    libsqlite3-0-3.36.0-1.2 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:61576
    P
    libsqlite3-0-3.28.0-3.6.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:71317
    P
    libsqlite3-0-3.28.0-3.6.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:103386
    P
    libsqlite3-0-3.28.0-3.6.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:96696
    P
    libsqlite3-0-3.28.0-3.6.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:89731
    P
    libsqlite3-0-3.28.0-3.6.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:47709
    P
    libgcrypt20-1.6.1-16.61.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48273
    P
    policycoreutils-2.5-10.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48165
    P
    libospf0-1.1.1-17.7.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47923
    P
    xfsprogs-4.15.0-1.12 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48236
    P
    logwatch-7.4.3-15.65 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48134
    P
    libjpeg-turbo-1.5.3-31.14.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47009
    P
    libasan2-32bit-5.3.1+r233831-9.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48007
    P
    flatpak-1.4.2-1.31 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47023
    P
    libgoa-1_0-0-3.20.4-7.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48069
    P
    libSDL-1_2-0-1.2.15-15.11.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47008
    P
    libarchive13-3.1.2-22.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47144
    P
    res-signingkeys-3.0.18-26.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47813
    P
    libxerces-c-3_1-3.1.1-12.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47337
    P
    libcgroup-tools-0.41.rc1-9.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47827
    P
    memcached-1.4.39-4.6.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47812
    P
    libxcb-dri2-0-1.10-4.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47469
    P
    perl-XML-LibXML-2.0019-5.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47948
    P
    apache-commons-httpclient-3.1-4.364 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47561
    P
    autofs-5.0.9-28.3.5 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48141
    P
    libldap-2_4-2-2.4.41-18.63.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:2432
    P
    taglib-1.11.1-4.9.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:62221
    P
    libsqlite3-0-3.28.0-3.9.2 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:71962
    P
    libsqlite3-0-3.28.0-3.9.2 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1933
    P
    libtdsodbc0-1.1.36-3.3.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:49446
    P
    Security update for php74 (Important)
    2021-08-06
    oval:org.opensuse.security:def:51606
    P
    Security update for libsolv (Important)
    2021-06-28
    oval:org.opensuse.security:def:48968
    P
    telepathy-idle-0.2.0-1.62 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48949
    P
    libtag1-32bit-1.9.1-1.265 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:70974
    P
    libgstgl-1_0-0-1.12.5-1.40 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:2436
    P
    NetworkManager-applet-1.8.10-3.39 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48365
    P
    apache-commons-beanutils-1.9.2-1.27 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:2442
    P
    colord-1.4.2-1.37 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48513
    P
    libjson-c2-0.11-2.15 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:2454
    P
    kernel-default-extra-4.12.14-23.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48969
    P
    typelib-1_0-EvinceDocument-3_0-3.20.2-6.22.9 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48727
    P
    java-1_7_0-openjdk-plugin-1.6.1-2.3.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48874
    P
    libuuid-devel-2.29.2-2.3 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:2468
    P
    libwpd-0_10-10-0.10.2-1.28 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48938
    P
    libpcrecpp0-32bit-8.39-8.3.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48811
    P
    libzmq3-4.0.4-6.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48928
    P
    libiso9660-8-0.90-6.3.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48873
    P
    libtag1-32bit-1.9.1-1.265 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:71087
    P
    python2-pywbem-0.11.0-2.21 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48950
    P
    libuuid-devel-2.29.2-7.14 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:51544
    P
    Security update for the Linux Kernel (Live Patch 35 for SLE 12 SP3) (Important)
    2021-04-28
    oval:org.opensuse.security:def:69784
    P
    Security update for the Linux Kernel (Important)
    2021-02-19
    oval:org.opensuse.security:def:69889
    P
    Security update for nodejs8 (Moderate)
    2021-01-26
    oval:org.opensuse.security:def:49300
    P
    Security update for python-paramiko (Important)
    2021-01-07
    oval:org.opensuse.security:def:67734
    P
    Security update for the Linux Kernel (Live Patch 19 for SLE 15) (Important)
    2020-12-07
    oval:org.opensuse.security:def:2513
    P
    xorg-x11-server-wayland-1.20.3-12.29 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2521
    P
    bogofilter-common-1.2.4-1.40 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:61886
    P
    libsqlite3-0-3.28.0-3.9.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:49040
    P
    libvdpau1-32bit-1.1.1-6.73 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:71627
    P
    libsqlite3-0-3.28.0-3.9.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2474
    P
    MozillaThunderbird-60.6.1-3.28.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107232
    P
    libsqlite3-0-3.28.0-3.9.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2483
    P
    enigmail-2.0.9-3.13.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:100566
    P
    libsqlite3-0-3.28.0-3.9.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2507
    P
    libwmf-0_2-7-0.2.8.4-2.30 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:116790
    P
    libsqlite3-0-3.28.0-3.9.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2523
    P
    dia-0.97.3-4.3.3 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:50099
    P
    skopeo on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66533
    P
    libsqlite3-0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73224
    P
    libsqlite3-0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50316
    P
    Security update for libxml2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49095
    P
    fuse on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50370
    P
    Security update for sqlite3 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:67634
    P
    kernel-firmware on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73106
    P
    ipmitool on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49544
    P
    libcdio++0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49701
    P
    libvdpau-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64300
    P
    libXext-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50195
    P
    libmwaw-0_3-3 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64387
    P
    libsqlite3-0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49939
    P
    apache2-mod_security2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49184
    P
    libksba-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50268
    P
    Security update for perl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50164
    P
    libstaroffice-0_0-0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50029
    P
    rarpd on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49238
    P
    libsqlite3-0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66441
    P
    libXi-devel on GA media (Moderate)
    2020-12-01
    oval:com.ubuntu.bionic:def:20199937000
    V
    CVE-2019-9937 on Ubuntu 18.04 LTS (bionic) - low.
    2019-03-22
    oval:com.ubuntu.cosmic:def:201999370000000
    V
    CVE-2019-9937 on Ubuntu 18.10 (cosmic) - low.
    2019-03-22
    oval:com.ubuntu.disco:def:201999370000000
    V
    CVE-2019-9937 on Ubuntu 19.04 (disco) - low.
    2019-03-22
    oval:com.ubuntu.cosmic:def:20199937000
    V
    CVE-2019-9937 on Ubuntu 18.10 (cosmic) - low.
    2019-03-22
    oval:com.ubuntu.bionic:def:201999370000000
    V
    CVE-2019-9937 on Ubuntu 18.04 LTS (bionic) - low.
    2019-03-22
    oval:com.ubuntu.trusty:def:20199937000
    V
    CVE-2019-9937 on Ubuntu 14.04 LTS (trusty) - low.
    2019-03-22
    oval:com.ubuntu.xenial:def:201999370000000
    V
    CVE-2019-9937 on Ubuntu 16.04 LTS (xenial) - low.
    2019-03-22
    oval:com.ubuntu.xenial:def:20199937000
    V
    CVE-2019-9937 on Ubuntu 16.04 LTS (xenial) - low.
    2019-03-22
    BACK
    sqlite sqlite 3.27.2
    sqlite sqlite 3.27.2
    ibm security guardium 10.1.4
    ibm security guardium 10.6