{"id":"CVE-2019-19603","details":"SQLite 3.30.1 mishandles certain SELECT statements with a nonexistent VIEW, leading to an application crash.","modified":"2026-02-01T04:13:41.438908Z","published":"2019-12-09T19:15:14.710Z","related":["ALSA-2021:4396","SUSE-SU-2021:2320-1","SUSE-SU-2021:3215-1","openSUSE-SU-2021:1058-1","openSUSE-SU-2021:2320-1"],"references":[{"type":"WEB","url":"https://lists.apache.org/thread.html/rc713534b10f9daeee2e0990239fa407e2118e4aa9e88a7041177497c%40%3Cissues.guacamole.apache.org%3E"},{"type":"ADVISORY","url":"https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf"},{"type":"ADVISORY","url":"https://github.com/sqlite/sqlite/commit/527cbd4a104cb93bf3994b3dd3619a6299a78b13"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20191223-0001/"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/4394-1/"},{"type":"ADVISORY","url":"https://www.oracle.com/security-alerts/cpuapr2020.html"},{"type":"ADVISORY","url":"https://www.sqlite.org/"},{"type":"FIX","url":"https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf"},{"type":"FIX","url":"https://github.com/sqlite/sqlite/commit/527cbd4a104cb93bf3994b3dd3619a6299a78b13"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpuapr2020.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/sqlite/sqlite","events":[{"introduced":"0"},{"fixed":"527cbd4a104cb93bf3994b3dd3619a6299a78b13"}]}],"versions":["cvs-to-fossil-cutover","experimental","fts3-refactor","version-3.10.0","version-3.11.0","version-3.11.1","version-3.12.0","version-3.13.0","version-3.14.0","version-3.15.0","version-3.16.0","version-3.19.0","version-3.19.1","version-3.19.2","version-3.21.0","version-3.22.0","version-3.23.0","version-3.23.1","version-3.24.0","version-3.25.0","version-3.26.0","version-3.27.0","version-3.28.0","version-3.29.0","version-3.30.0","version-3.6.10","version-3.6.15","version-3.7.10","version-3.7.11","version-3.7.12","version-3.7.12.1","version-3.7.13","version-3.7.14","version-3.7.15","version-3.7.16","version-3.7.16.1","version-3.7.16.2","version-3.7.17","version-3.7.2","version-3.7.4","version-3.7.5","version-3.7.6","version-3.7.6.1","version-3.7.7","version-3.7.8","version-3.7.9","version-3.8.0","version-3.8.1","version-3.8.10","version-3.8.10.1","version-3.8.11","version-3.8.11.1","version-3.8.2","version-3.8.3","version-3.8.4","version-3.8.4.1","version-3.8.5","version-3.8.6","version-3.8.7","version-3.8.7.1","version-3.8.8","version-3.8.9","version-3.9.0","version-3.9.1"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-19603.json","vanir_signatures":[{"digest":{"length":549,"function_hash":"27626154420001372684197020500987905409"},"signature_version":"v1","source":"https://github.com/sqlite/sqlite/commit/527cbd4a104cb93bf3994b3dd3619a6299a78b13","deprecated":false,"id":"CVE-2019-19603-633dc601","signature_type":"Function","target":{"function":"isShadowTableName","file":"src/build.c"}},{"digest":{"threshold":0.9,"line_hashes":["287497896093492558717730566123349902056","68078755522353012415862849008772074774","316924857588978521402910852767717284739","212195236596553332127943276576640944305","324300520921048957635732506972104711961","213332378117089353650062357664045575282","321667461324656957039245808403360856124","109516565254940296714267784274429599928","27886267803694925718781595726542831865","165614000285222875012276120822245002216","56174613741038714779478406230933867861","41373471911683750527177290269900368353","267216875257722564659356711824602778917","235964536311061423080369552431376023255","105147226921722913353088457384384708218","319610622448253636705003985192738509312","17814199897514829110021692228409468776","334119984944526948920047498120317882642","234766659524793751203695262721972211193","333990243645065370866821343180715188660","87674112754695016531360790925103079314","204566464292281694901325396982788126225","206543982201493453106971491728625454660"]},"signature_version":"v1","source":"https://github.com/sqlite/sqlite/commit/527cbd4a104cb93bf3994b3dd3619a6299a78b13","deprecated":false,"id":"CVE-2019-19603-8d7bac71","signature_type":"Line","target":{"file":"src/build.c"}},{"digest":{"threshold":0.9,"line_hashes":["3798063273630910954523208719825368993","161909305375505847269551325692640971615","163435075880835856004996898328017172720","232546748214512066955239099740306370909"]},"signature_version":"v1","source":"https://github.com/sqlite/sqlite/commit/527cbd4a104cb93bf3994b3dd3619a6299a78b13","deprecated":false,"id":"CVE-2019-19603-a0080460","signature_type":"Line","target":{"file":"src/sqliteInt.h"}},{"digest":{"length":694,"function_hash":"215797318871461761090532825553442516234"},"signature_version":"v1","source":"https://github.com/sqlite/sqlite/commit/527cbd4a104cb93bf3994b3dd3619a6299a78b13","deprecated":false,"id":"CVE-2019-19603-c886c206","signature_type":"Function","target":{"function":"sqlite3CheckObjectName","file":"src/build.c"}}]}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}