CVE-2021-44482: Input Validation
An issue was discovered in YottaDB through r1.32 and V7.0-000. A lack of input validation in calls to doverify in srunix/doverify.c allows attackers to attempt to jump to a NULL pointer by corrupting a function pointer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-44482?
The severity of CVE-2021-44482 is high with a rating of 7.5.
What is the affected software by CVE-2021-44482?
The affected software by CVE-2021-44482 includes Fisglobal Gt.m up to version 7.0-000 and Yottadb Yottadb up to version 1.32.
What is the vulnerability description of CVE-2021-44482?
CVE-2021-44482 is a vulnerability in YottaDB that allows attackers to attempt to jump to a NULL pointer by corrupting a function pointer.
How can I fix CVE-2021-44482?
To fix CVE-2021-44482, update to the latest version of YottaDB or Fisglobal Gt.m that includes the necessary security patches.
Where can I find more information about CVE-2021-44482?
More information about CVE-2021-44482 can be found at the following reference: [CVE-2021-44482](https://gitlab.com/YottaDB/DB/YDB/-/issues/828)