{"id":"CVE-2019-19923","details":"flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which the right-hand side is a view. This can cause a NULL pointer dereference (or incorrect results).","modified":"2026-04-16T00:06:28.746804750Z","published":"2019-12-24T16:15:11.260Z","related":["SUSE-SU-2021:2320-1","SUSE-SU-2021:3215-1","openSUSE-SU-2020:0189-1","openSUSE-SU-2020:0210-1","openSUSE-SU-2020:0233-1","openSUSE-SU-2021:1058-1","openSUSE-SU-2021:2320-1","openSUSE-SU-2024:10681-1","openSUSE-SU-2024:12948-1"],"references":[{"type":"WEB","url":"https://usn.ubuntu.com/4298-1/"},{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00010.html"},{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00015.html"},{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00025.html"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2020:0514"},{"type":"ADVISORY","url":"https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20200114-0003/"},{"type":"ADVISORY","url":"https://www.debian.org/security/2020/dsa-4638"},{"type":"ADVISORY","url":"https://www.oracle.com/security-alerts/cpuapr2020.html"},{"type":"FIX","url":"https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf"},{"type":"FIX","url":"https://github.com/sqlite/sqlite/commit/396afe6f6aa90a31303c183e11b2b2d4b7956b35"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpuapr2020.html"},{"type":"ARTICLE","url":"http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00010.html"},{"type":"ARTICLE","url":"http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00015.html"},{"type":"ARTICLE","url":"http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00025.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/sqlite/sqlite","events":[{"introduced":"0"},{"fixed":"396afe6f6aa90a31303c183e11b2b2d4b7956b35"}]}],"versions":["cvs-to-fossil-cutover","experimental","fts3-refactor","version-3.10.0","version-3.11.0","version-3.11.1","version-3.12.0","version-3.13.0","version-3.14.0","version-3.15.0","version-3.16.0","version-3.19.0","version-3.19.1","version-3.19.2","version-3.21.0","version-3.22.0","version-3.23.0","version-3.23.1","version-3.24.0","version-3.25.0","version-3.26.0","version-3.27.0","version-3.28.0","version-3.29.0","version-3.30.0","version-3.6.10","version-3.6.15","version-3.7.10","version-3.7.11","version-3.7.12","version-3.7.12.1","version-3.7.13","version-3.7.14","version-3.7.15","version-3.7.16","version-3.7.16.1","version-3.7.16.2","version-3.7.17","version-3.7.2","version-3.7.4","version-3.7.5","version-3.7.6","version-3.7.6.1","version-3.7.7","version-3.7.8","version-3.7.9","version-3.8.0","version-3.8.1","version-3.8.10","version-3.8.10.1","version-3.8.11","version-3.8.11.1","version-3.8.2","version-3.8.3","version-3.8.4","version-3.8.4.1","version-3.8.5","version-3.8.6","version-3.8.7","version-3.8.7.1","version-3.8.8","version-3.8.9","version-3.9.0","version-3.9.1"],"database_specific":{"vanir_signatures":[{"deprecated":false,"id":"CVE-2019-19923-134f638b","source":"https://github.com/sqlite/sqlite/commit/396afe6f6aa90a31303c183e11b2b2d4b7956b35","digest":{"function_hash":"330814732743507439986540557302774929713","length":5590},"signature_type":"Function","signature_version":"v1","target":{"file":"src/select.c","function":"flattenSubquery"}},{"source":"https://github.com/sqlite/sqlite/commit/396afe6f6aa90a31303c183e11b2b2d4b7956b35","id":"CVE-2019-19923-5fb5e80f","digest":{"line_hashes":["18104233075719913524635092338994927414","231876987339024958742979482512986350232","160277624447613318640615005514603846097","8615964068487288384404672935273546870","158745051547251140066162530979138522345","183413588476470140403235573409063477251","275703712529451719009097609695050452259"],"threshold":0.9},"deprecated":false,"signature_type":"Line","signature_version":"v1","target":{"file":"src/select.c"}}],"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-19923.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}