CVE-2019-9936
CVE Details
Last Update
11/7/24
NIST CVE Summary
In SQLite 3.27.2, using fts5 prefix queries inside a transaction could trigger a heap-based buffer over-read in fts5HashEntrySort in sqlite3.c, which may lead to an information leak. This is related to ext/fts5/fts5_hash.c.
Our Official Summary
Waiting on a fix from third party mongodb vendor.
CVE Severity
Status
Ongoing
Affected Products & Versions
- Palette VerteX airgap 4.4.14
- Palette VerteX 4.5.3, 4.5.8
- Palette Enterprise 4.5.3, 4.5.8
Revision History
- 1.0 08/16/2024 Initial Publication
- 2.0 08/17/2024 Added Palette VerteX airgap 4.4.14 to Affected Products
- 3.0 09/25/2024 CVE remediated in Palette VerteX airgap 4.4.18
- 4.0 10/14/2024 Added Palette Enterprise & Palette VerteX 4.5.3 to Affected Products
- 5.0 11/7/2024 Added Palette Enterprise & Palette VerteX 4.5.8 to Affected Products