Aller au contenu

Fiche vulnérabilité

CVE-2025-29087 : faille élevée sqlite sqlite (CVSS 7.5)

Description

In SQLite 3.44.0 through 3.49.0 before 3.49.1, the concat_ws() SQL function can cause memory to be written beyond the end of a malloc-allocated buffer. If the separator argument is attacker-controlled and has a large string (e.g., 2MB or more), an integer overflow occurs in calculating the size of the result buffer, and thus malloc may not allocate enough memory.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitation active
Non signalée par la CISA
Publication
7 avr. 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • sqlite sqlite

Références

Rechercher une autre vulnérabilité dans la base CVE