CVE-2024-0232
Dashboard / Vulnerabilities / CVE-2024-0232
Summary: Sqlite: use-after-free bug in jsonparseaddnodearray
Details: A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service.
References: https://access.redhat.com/downloads/content/package-browser/, https://lists.fedoraproject.org/archives/list/[email protected]/message/QDCMYQ3J45NHQ4EJREM3BJNNKB5BK4Y7/, https://www.sqlite.org/download.html, https://access.redhat.com/security/cve/CVE-2024-0232, https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/0xxx/CVE-2024-0232.json, https://nvd.nist.gov/vuln/detail/CVE-2024-0232, https://security.netapp.com/advisory/ntap-20240315-0007/, https://bugzilla.redhat.com/show_bug.cgi?id=2243754
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
