An integer overflow in the sqlite3KeyInfoFromExprList...
Moderate severity
Unreviewed
Published
Jul 29, 2025
to the GitHub Advisory Database
•
Updated Aug 11, 2025
Description
Published by the National Vulnerability Database
Jul 29, 2025
Published to the GitHub Advisory Database
Jul 29, 2025
Last updated
Aug 11, 2025
An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of service or disclose sensitive information from process memory via a crafted SELECT statement with a large number of expressions in the ORDER BY clause.
References