Skip to main content
Version: latest

CVE-2019-19244

CVE Details

Visit the official vulnerability details page for CVE-2019-19244 to learn more.

Initial Publication

10/25/2024

Last Update

12/16/2024

Third Party Dependency

sqlite-libs

NIST CVE Summary

sqlite3Select in select.c in SQLite 3.30.1 allows a crash if a sub-select uses both DISTINCT and window functions, and also has certain ORDER BY usage.

CVE Severity

7.5

Our Official Summary

This vulnerability found in SQLite can be remotely exploited by sending sql queries with DISTINCT, OVER and ORDER BY clauses. This will cause application crashes causing a denial of service attack.

Containers where this vulnerability is reported do not allow access to the sqlite database without an attacker gaining privileged access to the images. Even then risk of exploitation is low since there are controls to prevent execution of arbitrary commands.

Status

Ongoing

Affected Products & Versions

VersionPalette EnterprisePalette Enterprise AirgapVerteXVerteX Airgap
4.5.15⚠️ Impacted✅ No Impact⚠️ Impacted✅ No Impact
4.5.11⚠️ Impacted✅ No Impact⚠️ Impacted✅ No Impact
4.5.10⚠️ Impacted✅ No Impact⚠️ Impacted✅ No Impact
4.5.8⚠️ Impacted✅ No Impact⚠️ Impacted✅ No Impact
4.5.5⚠️ Impacted✅ No Impact⚠️ Impacted✅ No Impact
4.5.4⚠️ Impacted✅ No Impact⚠️ Impacted✅ No Impact
4.4.20⚠️ Impacted✅ No Impact⚠️ Impacted✅ No Impact

Revision History

DateRevision
12/16/2024Impacted versions changed from 4.5.4, 4.5.5, 4.5.8, 4.4.20, 4.5.10, 4.5.11 to 4.5.4, 4.5.5, 4.5.8, 4.4.20, 4.5.10, 4.5.11, 4.5.15
12/04/2024Official summary revised: This vulnerability found in SQLite can be remotely exploited by sending sql queries with DISTINCT, OVER and ORDER BY clauses. This will cause application crashes causing a denial of serviceattack. Containers where this vulnerability is reported do not allow access to the sqlite database without an attacker gaining privileged access to the images. Even then risk of exploitation is lowsince there are controls to prevent execution of arbitrary commands.
11/15/2024Impacted versions changed from 4.5.4, 4.5.5, 4.5.8, 4.4.20, 4.5.10 to 4.5.4, 4.5.5, 4.5.8, 4.4.20, 4.5.10, 4.5.11
11/15/2024Impacted versions changed from 4.5.4, 4.5.5, 4.5.8, 4.4.20 to 4.5.4, 4.5.5, 4.5.8, 4.4.20, 4.5.10
11/14/2024Impacted versions changed from 4.5.4, 4.5.5, 4.5.8 to 4.5.4, 4.5.5, 4.5.8, 4.4.20
11/10/2024Impacted versions changed from 4.5.4, 4.5.5 to 4.5.4, 4.5.5, 4.5.8
10/27/2024Impacted versions changed from 4.5.4 to 4.5.4, 4.5.5