CVE-2025-7458
An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of service or disclose sensitive information from process memory via a crafted SELECT statement with a large number of expressions in the ORDER BY clause.
Open
LOW (2.2)System detected CVE-2025-7458
System updated the risk assessment from 0 to 4.5
System recalculated raw risk assessment
System updated the risk assessment from 4.5 to 2.2
System recalculated raw risk assessment
System fixed CVE-2025-7458
System detected CVE-2025-7458 with a risk of 2.2
Add a comment
Last calculated at:
Affected component
debian/sqlite3