Site icon API Security Blog

K000141088: SQLite vulnerability CVE-2017-10989

Security Advisory Description The getNodeSize function in ext/rtree/rtree.c in SQLite through 3.19.3, as used in GDAL and other products, mishandles undersized RTree blobs in a crafted database, leading to a heap-based buffer over-read or possibly unspecified other impact. (CVE-2017-10989) Impact When this vulnerability is exploited, an attacker may be able to access sensitive…Read More

Exit mobile version