CVE-2019-19880: Debian Linux

High severity, CVSS 7.5. EPSS: 6.9% chance of exploitation in the next 30 days.

exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values in ORDER BY clauses of window definitions are mishandled.

Affected products

  • Debian Debian Linux: version 9.0 only; version 10.0 only
  • Netapp Cloud Backup: affected versions not specified
  • Opensuse Backports Sle: version 15.0 only
  • Opensuse Leap: version 15.1 only
  • Oracle MySQL Workbench: up to and including 8.0.19
  • Red Hat Enterprise Linux Desktop: version 6.0 only
  • Red Hat Enterprise Linux Server: version 6.0 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only
  • Siemens Sinec Infrastructure Network Services: before 1.0.1.1 (fixed in 1.0.1.1)
  • Sqlite Sqlite: version 3.30.1 only
  • Suse Package Hub: affected versions not specified

Published 2019-12-18. Last modified 2026-06-17.