Description
In SQLite 3.27.2, running fts5 prefix queries inside a transaction could trigger a heap-based buffer over-read in fts5HashEntrySort in sqlite3.c, which may lead to an information leak. This is related to ext/fts5/fts5_hash.c.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2010-2391 Vulnerability (CVE-2010-2391)
Jetty Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2024-6762)
Oracle HTTP Server Uncontrolled Resource Consumption Vulnerability (CVE-2022-25313)
Oracle HTTP Server CVE-2021-2480 Vulnerability (CVE-2021-2480)
WordPress Plugin Erident Custom Login and Dashboard Cross-Site Scripting (3.5.8)