In SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation.
{
"unresolved_ranges": [
{
"vendor_product": "apple:icloud",
"source": "CPE_FIELD",
"extracted_events": [
{
"fixed": "7.21"
}
],
"cpes": [
"cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:*"
]
},
{
"source": "CPE_FIELD",
"vendor_product": "apple:ipados",
"extracted_events": [
{
"fixed": "14.0"
}
],
"cpes": [
"cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*"
]
},
{
"source": "CPE_FIELD",
"vendor_product": "apple:iphone_os",
"extracted_events": [
{
"fixed": "14.0"
}
],
"cpes": [
"cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*"
]
},
{
"vendor_product": "apple:macos",
"source": "CPE_FIELD",
"extracted_events": [
{
"fixed": "11.0.1"
}
],
"cpes": [
"cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*"
]
},
{
"source": "CPE_FIELD",
"vendor_product": "apple:tvos",
"extracted_events": [
{
"fixed": "14.0"
}
],
"cpes": [
"cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*"
]
},
{
"source": "CPE_FIELD",
"vendor_product": "apple:watchos",
"extracted_events": [
{
"fixed": "7.0"
}
],
"cpes": [
"cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*"
]
},
{
"vendor_product": "canonical:ubuntu_linux",
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "20.04"
}
],
"cpes": [
"cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*"
]
},
{
"source": "CPE_FIELD",
"vendor_product": "oracle:communications_cloud_native_core_policy",
"extracted_events": [
{
"last_affected": "1.14.0"
}
],
"cpes": [
"cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.14.0:*:*:*:*:*:*:*"
]
},
{
"source": "CPE_FIELD",
"vendor_product": "oracle:communications_messaging_server",
"extracted_events": [
{
"last_affected": "8.1"
}
],
"cpes": [
"cpe:2.3:a:oracle:communications_messaging_server:8.1:*:*:*:*:*:*:*"
]
},
{
"source": "CPE_FIELD",
"vendor_product": "oracle:communications_network_charging_and_control",
"extracted_events": [
{
"last_affected": "6.0.1"
},
{
"last_affected": "12.0.2"
}
],
"cpes": [
"cpe:2.3:a:oracle:communications_network_charging_and_control:12.0.2:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:communications_network_charging_and_control:6.0.1:*:*:*:*:*:*:*"
]
},
{
"source": "CPE_FIELD",
"vendor_product": "oracle:enterprise_manager_ops_center",
"extracted_events": [
{
"last_affected": "12.4.0.0"
}
],
"cpes": [
"cpe:2.3:a:oracle:enterprise_manager_ops_center:12.4.0.0:*:*:*:*:*:*:*"
]
},
{
"source": "CPE_FIELD",
"vendor_product": "oracle:hyperion_infrastructure_technology",
"extracted_events": [
{
"last_affected": "11.1.2.4"
}
],
"cpes": [
"cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.1.2.4:*:*:*:*:*:*:*"
]
},
{
"source": "CPE_FIELD",
"vendor_product": "oracle:outside_in_technology",
"extracted_events": [
{
"last_affected": "8.5.4"
},
{
"last_affected": "8.5.5"
}
],
"cpes": [
"cpe:2.3:a:oracle:outside_in_technology:8.5.4:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:outside_in_technology:8.5.5:*:*:*:*:*:*:*"
]
},
{
"source": "CPE_FIELD",
"vendor_product": "siemens:sinec_infrastructure_network_services",
"extracted_events": [
{
"fixed": "1.0.1.1"
}
],
"cpes": [
"cpe:2.3:a:siemens:sinec_infrastructure_network_services:*:*:*:*:*:*:*:*"
]
}
]
}