System.Data.SQLite is vulnerable to Denial of Service (DoS)
56
Medium Risk
The bundled SQLite engine's sqlite3_db_config SQLITE_DBCONFIG_LOOKASIDE path multiplies lookaside slot size and count without promoting the product to 64-bit. Out-of-range arguments wrap that integer, so lookaside allocations can be undersized and the process crashes. There is no further bundled-engine release of this package. The engine fix applies a 64-bit multiply before allocating lookaside memory; applications need a native SQLite build that contains that change.
You are affected if you are using a version that falls within the vulnerable range and the SQLITE_DBCONFIG_LOOKASIDE configuration path can be reached.
System.Data.SQLite is vulnerable to Denial of Service (DoS) in versions 1.0.115.5 - 1.0.119.
Upgrade the System.Data.SQLite or System.Data.SQLite.Core library to the patch version. From version 2.x on this library does not bundle native SQLite anymore.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.