CVE-2019-19959: Canonical Ubuntu Linux
High severity, CVSS 7.5. EPSS: 3.2% chance of exploitation in the next 30 days.
ext/misc/zipfile.c in SQLite 3.30.1 mishandles certain uses of INSERT INTO in situations involving embedded '\0' characters in filenames, leading to a memory-management error that can be detected by (for example) valgrind.
Affected products
- Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 19.10 only
- Sqlite Sqlite: version 3.30.1 only
Published 2020-01-03. Last modified 2026-06-17.