An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.
References
| Link | Resource |
|---|---|
| https://gist.github.com/cnwangjihe/f496393f30f5ecec5b18c8f5ab072054 | Exploit Third Party Advisory |
| https://sqlite.org/forum/forumpost/761eac3c82 | Issue Tracking |
| https://sqlite.org/src/info/3d459f1fb1bd1b5e | Issue Tracking Patch |
Configurations
History
16 Apr 2026, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Sqlite
Sqlite sqlite |
|
| CPE | cpe:2.3:a:sqlite:sqlite:*:*:*:*:*:*:*:* | |
| References | () https://gist.github.com/cnwangjihe/f496393f30f5ecec5b18c8f5ab072054 - Exploit, Third Party Advisory | |
| References | () https://sqlite.org/forum/forumpost/761eac3c82 - Issue Tracking | |
| References | () https://sqlite.org/src/info/3d459f1fb1bd1b5e - Issue Tracking, Patch |
16 Mar 2026, 14:18
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-244 | |
| Summary |
|
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
12 Mar 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-12 19:16
Updated : 2026-04-16 21:15
NVD link : CVE-2025-70873
Mitre link : CVE-2025-70873
CVE.ORG link : CVE-2025-70873
JSON object : View
Products Affected
sqlite
- sqlite
CWE
CWE-244
Improper Clearing of Heap Memory Before Release ('Heap Inspection')
