[CVE-2022-35737] Stranger Strings: An exploitable flaw in SQLite
blog.trailofbits.com | vulnerability | CVE-2022-35737 | #memory-safety | #cve | #vulnerability-disclosure | #sqlite
Summary
Trail of Bits discloses CVE-2022-35737 in SQLite's printf implementation: present since 2000, fixed in 3.39.2. Large strings with %Q/%q/%w format types cause crashes on 64-bit systems, and the ! unicode flag enables worst-case arbitrary code execution.
- Published
- Collected
Skip to content