{"id":"USN-4019-1","summary":"sqlite3 vulnerabilities","details":"It was discovered that SQLite incorrectly handled certain SQL files.\nAn attacker could possibly use this issue to execute arbitrary code\nor cause a denial of service. This issue only affected Ubuntu 16.04\nLTS. (CVE-2017-2518, CVE-2017-2520)\n\nIt was discovered that SQLite incorrectly handled certain queries.\nAn attacker could possibly use this issue to execute arbitrary code.\nThis issue only affected Ubuntu 18.04 LTS and Ubuntu 18.10. (CVE-2018-20505)\n\nIt was discovered that SQLite incorrectly handled certain queries.\nAn attacker could possibly use this issue to execute arbitrary code.\nThis issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and\nUbuntu 18.10. (CVE-2018-20346, CVE-2018-20506)\n\nIt was discovered that SQLite incorrectly handled certain inputs.\nAn attacker could possibly use this issue to access sensitive information.\n(CVE-2019-8457)\n\nIt was discovered that SQLite incorrectly handled certain queries.\nAn attacker could possibly use this issue to access sensitive information.\nThis issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 18.10.\n(CVE-2019-9936)\n\nIt was discovered that SQLite incorrectly handled certain inputs.\nAn attacker could possibly use this issue to cause a crash or execute\narbitrary code. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS\nand Ubuntu 18.10. (CVE-2019-9937)\n\nIt was discovered that SQLite incorrectly handled certain inputs.\nAn attacker could possibly use this issue to cause a denial of service.\nThis issue only affected Ubuntu 16.04 LTS. (CVE-2016-6153)\n\nIt was discovered that SQLite incorrectly handled certain databases.\nAn attacker could possibly use this issue to access sensitive information.\nThis issue only affected Ubuntu 16.04 LTS. (CVE-2017-10989)\n\nIt was discovered that SQLite incorrectly handled certain files.\nAn attacker could possibly use this issue to cause a denial of service.\nThis issue only affected Ubuntu 16.04 LTS. (CVE-2017-13685)\n\nIt was discovered that SQLite incorrectly handled certain queries.\nAn attacker could possibly use this issue to execute arbitrary code or\ncause a denial of service. This issue only affected Ubuntu 16.04 LTS.\n(CVE-2017-2519)\n","modified":"2026-02-10T04:41:33Z","published":"2019-06-19T15:32:19Z","related":["UBUNTU-CVE-2016-6153","UBUNTU-CVE-2017-10989","UBUNTU-CVE-2017-13685","UBUNTU-CVE-2017-2518","UBUNTU-CVE-2017-2519","UBUNTU-CVE-2017-2520","UBUNTU-CVE-2018-20346","UBUNTU-CVE-2018-20505","UBUNTU-CVE-2018-20506","UBUNTU-CVE-2019-8457","UBUNTU-CVE-2019-9936","UBUNTU-CVE-2019-9937"],"upstream":["CVE-2016-6153","CVE-2017-10989","CVE-2017-13685","CVE-2017-2518","CVE-2017-2519","CVE-2017-2520","CVE-2018-20346","CVE-2018-20505","CVE-2018-20506","CVE-2019-8457","CVE-2019-9936","CVE-2019-9937","UBUNTU-CVE-2016-6153","UBUNTU-CVE-2017-10989","UBUNTU-CVE-2017-13685","UBUNTU-CVE-2017-2518","UBUNTU-CVE-2017-2519","UBUNTU-CVE-2017-2520","UBUNTU-CVE-2018-20346","UBUNTU-CVE-2018-20505","UBUNTU-CVE-2018-20506","UBUNTU-CVE-2019-8457","UBUNTU-CVE-2019-9936","UBUNTU-CVE-2019-9937"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-4019-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2016-6153"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2017-2518"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2017-2519"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2017-2520"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2017-10989"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2017-13685"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2018-20346"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2018-20505"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2018-20506"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2019-8457"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2019-9936"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2019-9937"}],"affected":[{"package":{"name":"sqlite3","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/sqlite3@3.11.0-1ubuntu1.2?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.11.0-1ubuntu1.2"}]}],"versions":["3.8.11.1-1","3.9.1-2","3.9.2-1","3.10.0-1","3.10.1-1","3.10.2-1","3.11.0-1ubuntu1","3.11.0-1ubuntu1.1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_version":"3.11.0-1ubuntu1.2","binary_name":"lemon"},{"binary_version":"3.11.0-1ubuntu1.2","binary_name":"libsqlite3-0"},{"binary_version":"3.11.0-1ubuntu1.2","binary_name":"libsqlite3-dev"},{"binary_version":"3.11.0-1ubuntu1.2","binary_name":"libsqlite3-tcl"},{"binary_version":"3.11.0-1ubuntu1.2","binary_name":"sqlite3"}]},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:16.04:LTS","cves":[{"severity":[{"score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","type":"CVSS_V3"},{"score":"negligible","type":"Ubuntu"}],"id":"CVE-2016-6153"},{"severity":[{"score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"low","type":"Ubuntu"}],"id":"CVE-2017-2518"},{"severity":[{"score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"negligible","type":"Ubuntu"}],"id":"CVE-2017-2519"},{"severity":[{"score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"low","type":"Ubuntu"}],"id":"CVE-2017-2520"},{"severity":[{"score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"negligible","type":"Ubuntu"}],"id":"CVE-2017-10989"},{"severity":[{"score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"negligible","type":"Ubuntu"}],"id":"CVE-2017-13685"},{"severity":[{"score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2018-20346"},{"severity":[{"score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2018-20506"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2019-8457"},{"severity":[{"score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2019-9936"},{"severity":[{"score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"low","type":"Ubuntu"}],"id":"CVE-2019-9937"}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-4019-1.json"}},{"package":{"name":"sqlite3","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/sqlite3@3.22.0-1ubuntu0.1?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.22.0-1ubuntu0.1"}]}],"versions":["3.19.3-3","3.20.1-2","3.21.0-1","3.22.0-1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_version":"3.22.0-1ubuntu0.1","binary_name":"lemon"},{"binary_version":"3.22.0-1ubuntu0.1","binary_name":"libsqlite3-0"},{"binary_version":"3.22.0-1ubuntu0.1","binary_name":"libsqlite3-dev"},{"binary_version":"3.22.0-1ubuntu0.1","binary_name":"libsqlite3-tcl"},{"binary_version":"3.22.0-1ubuntu0.1","binary_name":"sqlite3"}]},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:18.04:LTS","cves":[{"severity":[{"score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2018-20346"},{"severity":[{"score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"low","type":"Ubuntu"}],"id":"CVE-2018-20505"},{"severity":[{"score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2018-20506"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2019-8457"},{"severity":[{"score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2019-9936"},{"severity":[{"score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"low","type":"Ubuntu"}],"id":"CVE-2019-9937"}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-4019-1.json"}}],"schema_version":"1.7.3"}