CVE-2015-3414: Apple Mac OS X
High severity, CVSS 7.5. EPSS: 4.7% chance of exploitation in the next 30 days.
SQLite before 3.8.9 does not properly implement the dequoting of collation-sequence names, which allows context-dependent attackers to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other impact via a crafted COLLATE clause, as demonstrated by COLLATE"""""""" at the end of a SELECT statement.
Affected products
- Apple Mac OS X: version 10.10.5 only
- Apple watchOS: version 1.0.1 only
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.04 only
- Debian Debian Linux: version 8.0 only
- PHP PHP: from 5.4.0, before 5.4.42 (fixed in 5.4.42); from 5.5.0, before 5.5.26 (fixed in 5.5.26); from 5.6.0, before 5.6.10 (fixed in 5.6.10)
- Sqlite Sqlite: up to and including 3.8.8.3
Published 2015-04-24. Last modified 2026-06-17.