CVE-2019-19959: Canonical Ubuntu Linux

High severity, CVSS 7.5. EPSS: 3.2% chance of exploitation in the next 30 days.

ext/misc/zipfile.c in SQLite 3.30.1 mishandles certain uses of INSERT INTO in situations involving embedded '\0' characters in filenames, leading to a memory-management error that can be detected by (for example) valgrind.

Affected products

  • Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 19.10 only
  • Sqlite Sqlite: version 3.30.1 only

Published 2020-01-03. Last modified 2026-06-17.