An exploitable use-after-free vulnerability exists in the window function of SQLite3 3.26.0 and 3.27.0 of the C programming library. An attacker can send a malicious SQL command to trigger this vulnerability. Cisco Talos worked with the software to ensure that these issues are resolved and that an update is available for affected customers. Read the complete vulnerability advisory here for additional information. Back to the page you came from: http://www.ciscoTalos-2018-0777/CVE-2019-5018.”]
Source: https://blog.talosintelligence.com/2019/05/vulnerability-spotlight-remote-code.html