Impact
The vulnerability allows a caller to supply a crafted source database name to the sqlcipher_export convenience function. The function temporarily clears defensive restrictions while performing dynamic schema manipulation, and a flaw in handling the source name permits execution of arbitrary SQL statements that would normally be blocked. This can lead to modifications of the sqlite_schema table and cause database corruption. The weakness is tracked as CWE-89, reflecting unsanitized SQL input.
Affected Systems
Zetetic SQLCipher versions prior to 4.15.0 are affected. The issue concerns the sqlcipher_export function available in these releases and applies to any database instance accessed by users of those versions.
Risk and Exploitability
Based on the description, it is inferred that the attacker would need local or application-level access to supply a crafted source database name to sqlcipher_export. The CVSS score of 2.1 indicates low overall severity, and no EPSS information is available, so the statistical exploitation likelihood is unknown. The vulnerability is not listed in the CISA KEV catalog. Successful exploitation would corrupt the database and could result in data loss, but the impact is limited to the database instance being operated on.
OpenCVE Enrichment