{"id":"CVE-2020-15358","details":"In SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation.","aliases":["A-192605364","ASB-A-192605364","BIT-sqlite-2020-15358"],"modified":"2026-05-15T12:04:04.674981827Z","published":"2020-06-27T12:15:11.187Z","related":["CGA-mjm2-pqv4-xjvg","SUSE-SU-2021:2320-1","SUSE-SU-2021:3215-1","openSUSE-SU-2021:1058-1","openSUSE-SU-2021:2320-1"],"database_specific":{"unresolved_ranges":[{"source":"CPE_FIELD","vendor_product":"apple:icloud","extracted_events":[{"fixed":"7.21"}],"cpes":["cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:*"]},{"source":"CPE_FIELD","vendor_product":"apple:ipados","extracted_events":[{"fixed":"14.0"}],"cpes":["cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*"]},{"source":"CPE_FIELD","vendor_product":"apple:iphone_os","extracted_events":[{"fixed":"14.0"}],"cpes":["cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*"]},{"source":"CPE_FIELD","vendor_product":"apple:macos","extracted_events":[{"fixed":"11.0.1"}],"cpes":["cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*"]},{"source":"CPE_FIELD","vendor_product":"apple:tvos","extracted_events":[{"fixed":"14.0"}],"cpes":["cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*"]},{"source":"CPE_FIELD","vendor_product":"apple:watchos","extracted_events":[{"fixed":"7.0"}],"cpes":["cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*"]},{"source":"CPE_FIELD","vendor_product":"canonical:ubuntu_linux","extracted_events":[{"last_affected":"20.04"}],"cpes":["cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*"]},{"source":"CPE_FIELD","vendor_product":"oracle:communications_cloud_native_core_policy","cpes":["cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.14.0:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"1.14.0"}]},{"source":"CPE_FIELD","vendor_product":"oracle:communications_messaging_server","cpes":["cpe:2.3:a:oracle:communications_messaging_server:8.1:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"8.1"}]},{"source":"CPE_FIELD","vendor_product":"oracle:communications_network_charging_and_control","extracted_events":[{"last_affected":"6.0.1"},{"last_affected":"12.0.2"}],"cpes":["cpe:2.3:a:oracle:communications_network_charging_and_control:12.0.2:*:*:*:*:*:*:*","cpe:2.3:a:oracle:communications_network_charging_and_control:6.0.1:*:*:*:*:*:*:*"]},{"source":"CPE_FIELD","vendor_product":"oracle:enterprise_manager_ops_center","extracted_events":[{"last_affected":"12.4.0.0"}],"cpes":["cpe:2.3:a:oracle:enterprise_manager_ops_center:12.4.0.0:*:*:*:*:*:*:*"]},{"source":"CPE_FIELD","vendor_product":"oracle:hyperion_infrastructure_technology","cpes":["cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.1.2.4:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"11.1.2.4"}]},{"source":"CPE_FIELD","vendor_product":"oracle:outside_in_technology","extracted_events":[{"last_affected":"8.5.4"},{"last_affected":"8.5.5"}],"cpes":["cpe:2.3:a:oracle:outside_in_technology:8.5.4:*:*:*:*:*:*:*","cpe:2.3:a:oracle:outside_in_technology:8.5.5:*:*:*:*:*:*:*"]},{"source":"CPE_FIELD","vendor_product":"siemens:sinec_infrastructure_network_services","cpes":["cpe:2.3:a:siemens:sinec_infrastructure_network_services:*:*:*:*:*:*:*:*"],"extracted_events":[{"fixed":"1.0.1.1"}]}]},"references":[{"type":"ADVISORY","url":"http://seclists.org/fulldisclosure/2020/Dec/32"},{"type":"ADVISORY","url":"http://seclists.org/fulldisclosure/2020/Nov/19"},{"type":"ADVISORY","url":"http://seclists.org/fulldisclosure/2020/Nov/20"},{"type":"ADVISORY","url":"http://seclists.org/fulldisclosure/2020/Nov/22"},{"type":"ADVISORY","url":"http://seclists.org/fulldisclosure/2021/Feb/14"},{"type":"ADVISORY","url":"https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202007-26"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20200709-0001/"},{"type":"ADVISORY","url":"https://support.apple.com/kb/HT211843"},{"type":"ADVISORY","url":"https://support.apple.com/kb/HT211844"},{"type":"ADVISORY","url":"https://support.apple.com/kb/HT211847"},{"type":"ADVISORY","url":"https://support.apple.com/kb/HT211850"},{"type":"ADVISORY","url":"https://support.apple.com/kb/HT211931"},{"type":"ADVISORY","url":"https://support.apple.com/kb/HT212147"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/4438-1/"},{"type":"ADVISORY","url":"https://www.oracle.com/security-alerts/cpujan2021.html"},{"type":"ADVISORY","url":"https://www.oracle.com/security-alerts/cpuoct2020.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpuApr2021.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpuapr2022.html"},{"type":"FIX","url":"https://www.sqlite.org/src/info/10fa79d00f8091e5"},{"type":"FIX","url":"https://www.sqlite.org/src/timeline?p=version-3.32.3&bt=version-3.32.2"},{"type":"EVIDENCE","url":"https://www.sqlite.org/src/tktview?name=8f157e8010"}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}