SQLite through 3.31.1 allows attackers to cause a denial of service (segmentation fault) via a malformed window-function query because the AggInfo object's initialization is mishandled.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*"
],
"source": "CPE_FIELD",
"vendor_product": "canonical:ubuntu_linux",
"extracted_events": [
{
"last_affected": "16.04"
},
{
"last_affected": "18.04"
},
{
"last_affected": "19.10"
},
{
"last_affected": "20.04"
}
]
},
{
"cpes": [
"cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*",
"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"vendor_product": "debian:debian_linux",
"extracted_events": [
{
"last_affected": "8.0"
},
{
"last_affected": "9.0"
}
]
},
{
"cpes": [
"cpe:2.3:a:oracle:communications_element_manager:*:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"vendor_product": "oracle:communications_element_manager",
"extracted_events": [
{
"introduced": "8.2.0"
},
{
"last_affected": "8.2.2"
}
]
},
{
"cpes": [
"cpe:2.3:o:oracle:communications_messaging_server:8.1:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:communications_messaging_server",
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "8.1"
}
]
},
{
"cpes": [
"cpe:2.3:a:oracle:communications_network_charging_and_control:*:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:communications_network_charging_and_control:12.0.2:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:communications_network_charging_and_control:6.0.1:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"vendor_product": "oracle:communications_network_charging_and_control",
"extracted_events": [
{
"introduced": "12.0.0"
},
{
"last_affected": "12.0.3"
},
{
"last_affected": "6.0.1"
},
{
"last_affected": "12.0.2"
}
]
},
{
"cpes": [
"cpe:2.3:a:oracle:communications_session_report_manager:*:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"vendor_product": "oracle:communications_session_report_manager",
"extracted_events": [
{
"introduced": "8.2.0"
},
{
"last_affected": "8.2.2"
}
]
},
{
"cpes": [
"cpe:2.3:a:oracle:communications_session_route_manager:*:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"vendor_product": "oracle:communications_session_route_manager",
"extracted_events": [
{
"introduced": "8.2.0"
},
{
"last_affected": "8.2.2"
}
]
},
{
"cpes": [
"cpe:2.3:a:oracle:enterprise_manager_ops_center:12.4.0.0:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"vendor_product": "oracle:enterprise_manager_ops_center",
"extracted_events": [
{
"last_affected": "12.4.0.0"
}
]
},
{
"cpes": [
"cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.1.2.4:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"vendor_product": "oracle:hyperion_infrastructure_technology",
"extracted_events": [
{
"last_affected": "11.1.2.4"
}
]
},
{
"cpes": [
"cpe:2.3:a:oracle:instantis_enterprisetrack:17.1:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:instantis_enterprisetrack:17.2:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:instantis_enterprisetrack:17.3:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"vendor_product": "oracle:instantis_enterprisetrack",
"extracted_events": [
{
"last_affected": "17.1"
},
{
"last_affected": "17.2"
},
{
"last_affected": "17.3"
}
]
},
{
"cpes": [
"cpe:2.3:a:oracle:mysql_workbench:*:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"vendor_product": "oracle:mysql_workbench",
"extracted_events": [
{
"last_affected": "8.0.22"
}
]
},
{
"cpes": [
"cpe:2.3:a:oracle:outside_in_technology:8.5.4:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:outside_in_technology:8.5.5:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"vendor_product": "oracle:outside_in_technology",
"extracted_events": [
{
"last_affected": "8.5.4"
},
{
"last_affected": "8.5.5"
}
]
},
{
"cpes": [
"cpe:2.3:a:oracle:zfs_storage_appliance_kit:8.8:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"vendor_product": "oracle:zfs_storage_appliance_kit",
"extracted_events": [
{
"last_affected": "8.8"
}
]
},
{
"cpes": [
"cpe:2.3:a:siemens:sinec_infrastructure_network_services:*:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"vendor_product": "siemens:sinec_infrastructure_network_services",
"extracted_events": [
{
"fixed": "1.0.1.1"
}
]
},
{
"cpes": [
"cpe:2.3:a:tenable:tenable.sc:*:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"vendor_product": "tenable:tenable.sc",
"extracted_events": [
{
"fixed": "5.19.0"
}
]
}
]
}