CVE-2022-21227
Summary
| CVE | CVE-2022-21227 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-05-01 16:15:00 UTC |
| Updated | 2022-05-11 14:10:00 UTC |
| Description | The package sqlite3 before 5.0.3 are vulnerable to Denial of Service (DoS) which will invoke the toString function of the passed parameter. If passed an invalid Function object it will throw and crash the V8 engine. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| bug: fix segfault of invalid toString() object (#1450) · TryGhost/node-sqlite3@593c9d4 · GitHub | MISC | github.com | |
| Denial of Service (DoS) in sqlite3 | CVE-2022-21227 | Snyk | MISC | snyk.io | |
| Denial of Service (DoS) in org.webjars.npm:sqlite3 | CVE-2022-21227 | Snyk | MISC | snyk.io | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Cristian-Alexandru Staicu
Legacy QID Mappings
- 180867 Debian Security Update for node-sqlite3 (CVE-2022-21227)