1.
blog.trailofbits.com | vulnerability | | original ↗ | #memory-safety | #cve | #vulnerability-disclosure | #sqlite
Trail of Bits discloses CVE-2022-35737 in SQLite's printf implementation: present since 2000, fixed in 3.39.2. Large strings with %Q/%q/%w format types cause crashes on 64-bit systems, and the ! unicode flag enables worst-case arbitrary code execution.
Skip to content