In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a compound SELECT statement.
{
"unresolved_ranges": [
{
"vendor_product": "oracle:communications_network_charging_and_control",
"extracted_events": [
{
"introduced": "12.0.0"
},
{
"last_affected": "12.0.3"
}
],
"cpes": [
"cpe:2.3:a:oracle:communications_network_charging_and_control:*:*:*:*:*:*:*:*"
],
"source": "CPE_RANGE"
},
{
"vendor_product": "oracle:mysql_workbench",
"extracted_events": [
{
"last_affected": "8.0.22"
}
],
"cpes": [
"cpe:2.3:a:oracle:mysql_workbench:*:*:*:*:*:*:*:*"
],
"source": "CPE_RANGE"
},
{
"vendor_product": "siemens:sinec_infrastructure_network_services",
"extracted_events": [
{
"fixed": "1.0.1.1"
}
],
"cpes": [
"cpe:2.3:a:siemens:sinec_infrastructure_network_services:*:*:*:*:*:*:*:*"
],
"source": "CPE_RANGE"
},
{
"vendor_product": "tenable:tenable.sc",
"extracted_events": [
{
"last_affected": "5.19.0"
}
],
"cpes": [
"cpe:2.3:a:tenable:tenable.sc:*:*:*:*:*:*:*:*"
],
"source": "CPE_RANGE"
},
{
"vendor_product": "oracle:communications_messaging_server",
"extracted_events": [
{
"last_affected": "8.1"
}
],
"cpes": [
"cpe:2.3:o:oracle:communications_messaging_server:8.1:*:*:*:*:*:*:*"
],
"source": "CPE_STRING"
},
{
"vendor_product": "oracle:communications_network_charging_and_control",
"extracted_events": [
{
"last_affected": "6.0.1"
},
{
"last_affected": "12.0.2"
}
],
"cpes": [
"cpe:2.3:a:oracle:communications_network_charging_and_control:12.0.2:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:communications_network_charging_and_control:6.0.1:*:*:*:*:*:*:*"
],
"source": "CPE_STRING"
},
{
"vendor_product": "oracle:enterprise_manager_ops_center",
"extracted_events": [
{
"last_affected": "12.4.0.0"
}
],
"cpes": [
"cpe:2.3:a:oracle:enterprise_manager_ops_center:12.4.0.0:*:*:*:*:*:*:*"
],
"source": "CPE_STRING"
},
{
"vendor_product": "oracle:hyperion_infrastructure_technology",
"extracted_events": [
{
"last_affected": "11.1.2.4"
}
],
"cpes": [
"cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.1.2.4:*:*:*:*:*:*:*"
],
"source": "CPE_STRING"
},
{
"vendor_product": "oracle:outside_in_technology",
"extracted_events": [
{
"last_affected": "8.5.4"
},
{
"last_affected": "8.5.5"
}
],
"cpes": [
"cpe:2.3:a:oracle:outside_in_technology:8.5.4:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:outside_in_technology:8.5.5:*:*:*:*:*:*:*"
],
"source": "CPE_STRING"
},
{
"vendor_product": "oracle:zfs_storage_appliance_kit",
"extracted_events": [
{
"last_affected": "8.8"
}
],
"cpes": [
"cpe:2.3:a:oracle:zfs_storage_appliance_kit:8.8:*:*:*:*:*:*:*"
],
"source": "CPE_STRING"
}
]
}{
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "3.31.1"
}
],
"cpe": "cpe:2.3:a:sqlite:sqlite:*:*:*:*:*:*:*:*",
"source": "CPE_RANGE"
}