CVE-2025-7458
An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of service or disclose sensitive information from process memory via a crafted SELECT statement with a large number of expressions in the ORDER BY clause.
System detected CVE-2025-7458
System detected CVE-2025-7458
System updated the risk assessment from 0 to 4.5
System recalculated raw risk assessment
System updated the risk assessment from 0 to 4.5
System recalculated raw risk assessment
System updated the risk assessment from 4.5 to 2.2
System recalculated raw risk assessment
System updated the risk assessment from 4.5 to 2.2
System recalculated raw risk assessment
System fixed CVE-2025-7458
System fixed CVE-2025-7458
System detected CVE-2025-7458 with a risk of 2.2
Add a comment
Affected component
debian/sqlite3