CNNVD-202507-2004 Information

CNNVD ID

CNNVD-202507-2004

CVE-2025-6965

  • CNNVD Published: 2025-07-15

Description (Chinese)

SQLite是SQLite开源的一款轻型的数据库,是遵守ACID的关系型数据库管理系统。 SQLite 3.50.2之前版本存在安全漏洞,该漏洞源于聚合项数量可能超过可用列数,可能导致内存损坏。

Description (English)

SQLite is a light database from the SQLite open source and follows the ACID relationship database management system. Prior to SQLite 3.50.2, there was a security loophole, which stemmed from the fact that the number of polymers might exceed the number of columns available and could result in memory damage.

Hazard Level

Low

Vulnerability Type

其他

Affected Vendor

Square Box Systems

Published

2025-07-15

Last Modified

2026-02-24

References

https://www.sqlite.org/src/info/5508b56fd24016c13981ec280ecdd833007c9d8dd595edb295b984c2b487b5c8 https://access.redhat.com/security/cve/cve-2025-6965 https://www.oracle.com/security-alerts/cpuoct2025.html https://nvd.nist.gov/vuln/detail/CVE-2025-6965 https://vigilance.fr/vulnerability/SQLite-out-of-bounds-memory-reading-dated-01-07-2025-47578 https://www.oracle.com/security-alerts/cpujan2026.html

Patch

https://www.sqlite.org/

Share on: