CVE-2025-29087

In SQLite 3.44.0 through 3.49.0 before 3.49.1, the concat_ws() SQL function can cause memory to be written beyond the end of a malloc-allocated buffer. If the separator argument is attacker-controlled and has a large string (e.g., 2MB or more), an integer overflow occurs in calculating the size of the result buffer, and thus malloc may not allocate enough memory.
Configurations

No configuration.

History

14 Apr 2025, 14:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 3.2
Summary (en) Sqlite 3.49.0 is susceptible to integer overflow through the concat function. (en) In SQLite 3.44.0 through 3.49.0 before 3.49.1, the concat_ws() SQL function can cause memory to be written beyond the end of a malloc-allocated buffer. If the separator argument is attacker-controlled and has a large string (e.g., 2MB or more), an integer overflow occurs in calculating the size of the result buffer, and thus malloc may not allocate enough memory.
References
  • () https://sqlite.org/releaselog/3_49_1.html -
  • () https://www.sqlite.org/cves.html -

08 Apr 2025, 14:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
Summary
  • (es) Sqlite 3.49.0 es susceptible al desbordamiento de enteros a través de la función concat.
CWE CWE-190

07 Apr 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-07 20:15

Updated : 2025-04-15 16:16


NVD link : CVE-2025-29087

Mitre link : CVE-2025-29087

CVE.ORG link : CVE-2025-29087


JSON object : View

Products Affected

No product.

CWE
CWE-190

Integer Overflow or Wraparound