Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

[CVE-2022-35737] Stranger Strings: An exploitable flaw in SQLite

Summary

Trail of Bits discloses CVE-2022-35737 in SQLite's printf implementation: present since 2000, fixed in 3.39.2. Large strings with %Q/%q/%w format types cause crashes on 64-bit systems, and the ! unicode flag enables worst-case arbitrary code execution.
Published
Collected

original ↗

Related coverage

back