CVE-2019-16168: Canonical Ubuntu Linux
Medium severity, CVSS 6.5. EPSS: 4.3% chance of exploitation in the next 30 days.
In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validation of a sqlite_stat1 sz field, aka a "severe division by zero in the query planner."
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 16.04 only; version 18.04 only; version 19.04 only; version 19.10 only
- Debian Debian Linux: version 9.0 only
- Fedoraproject Fedora: version 30 only
- McAfee Policy Auditor: before 6.5.1 (fixed in 6.5.1)
- Netapp Active Iq Unified Manager: from 7.3; from 9.5
- Netapp E-Series Santricity OS Controller: from 11.0.0, up to and including 11.60.3
- Netapp Oncommand Insight: affected versions not specified
- Netapp Oncommand Workflow Automation: affected versions not specified
- Netapp Ontap Select Deploy Administration Utility: affected versions not specified
- Netapp Santricity Unified Manager: affected versions not specified
- Netapp Steelstore Cloud Integrated Storage: affected versions not specified
- Oracle Communications Design Studio: version 7.3.4.3.0 only; version 7.3.5.5.0 only; version 7.4.0.4.0 only
- Oracle JDK: version 1.8.0 only
- Oracle JRE: version 1.8.0 only
- Oracle MySQL: from 8.0.0, up to and including 8.0.18
- Oracle Outside In Technology: version 8.5.4 only
- Oracle Solaris: version 11 only
- Oracle ZFS Storage Appliance: version 8.8 only
- Sqlite Sqlite: from 3.8.5, up to and including 3.29.0
- Tenable Nessus Agent: up to and including 8.2.3
Published 2019-09-09. Last modified 2026-06-17.