CVE-2019-19244High· 7.5▾ Twilightsqlite3Select in select.c in SQLite 3.30.1 allows a crash if a sub-select uses both DISTINCT and window functions, and also has certain ORDER BY usage.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.7 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
3.3%
sqlite3Select in select.c in SQLite 3.30.1 allows a crash if a sub-select uses both DISTINCT and window functions, and also has certain ORDER BY usage.
sqlite = 3.30.1ubuntu_linux = 19.04ubuntu_linux = 19.10mysql_workbench <= 8.0.19sinec_infrastructure_network_services < 1.0.1.1Upgrade past the affected range:
sinec_infrastructure_network_services 1.0.1.1Connected by shared product, vendor, weakness, or advisory.