sqlcipher/android-database-sqlcipher

Vulnerability in SQLite3.39.2 BDSA-2023-3627

sankar-gp opened this issue · 1 comments

Our internal tool reported that there is a Vulnerability in SQLite3.39.2

BDSA-2023-3627

A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service.

dupe of #641