diff -r e1b1be597736 Lib/sqlite3/test/regression.py --- a/Lib/sqlite3/test/regression.py Tue Sep 09 19:07:49 2014 +0300 +++ b/Lib/sqlite3/test/regression.py Tue Sep 09 20:53:46 2014 +0300 @@ -336,6 +336,16 @@ sqlite.connect, ":memory:", isolation_level=123) + def CheckNullCharacter(self): + # Issue #21147 + con = sqlite.connect(":memory:") + self.assertRaises(ValueError, con, "\0select 1") + self.assertRaises(ValueError, con, "select 1\0") + cur = con.cursor() + self.assertRaises(ValueError, cur.execute, " \0select 2") + self.assertRaises(ValueError, cur.execute, "select 2\0") + + def suite(): regression_suite = unittest.makeSuite(RegressionTests, "Check") return unittest.TestSuite((regression_suite,)) diff -r e1b1be597736 Modules/_sqlite/connection.c --- a/Modules/_sqlite/connection.c Tue Sep 09 19:07:49 2014 +0300 +++ b/Modules/_sqlite/connection.c Tue Sep 09 20:53:46 2014 +0300 @@ -1261,7 +1261,8 @@ if (rc == PYSQLITE_TOO_MUCH_SQL) { PyErr_SetString(pysqlite_Warning, "You can only execute one statement at a time."); } else if (rc == PYSQLITE_SQL_WRONG_TYPE) { - PyErr_SetString(pysqlite_Warning, "SQL is of wrong type. Must be string or unicode."); + if (PyErr_ExceptionMatches(PyExc_TypeError)) + PyErr_SetString(pysqlite_Warning, "SQL is of wrong type. Must be string."); } else { (void)pysqlite_statement_reset(statement); _pysqlite_seterror(self->db, NULL); diff -r e1b1be597736 Modules/_sqlite/statement.c --- a/Modules/_sqlite/statement.c Tue Sep 09 19:07:49 2014 +0300 +++ b/Modules/_sqlite/statement.c Tue Sep 09 20:53:46 2014 +0300 @@ -63,6 +63,10 @@ rc = PYSQLITE_SQL_WRONG_TYPE; return rc; } + if (strlen(sql_cstr) != (size_t)sql_cstr_len) { + PyErr_SetString(PyExc_ValueError, "the query contains a null character"); + return PYSQLITE_SQL_WRONG_TYPE; + } self->in_weakreflist = NULL; Py_INCREF(sql);